WP SVG Icons <= 3.2.2 - Cross-Site Request Forgery to Remote Code Execution
2019-08-09 00:00
ZeroauthStrategic Overview
StatusPatched in 3.2.3
Affected PluginWP SVG Icons
Affected Version
< 3.2.3CVSS8.8High
CVE
CVE-2019-14216Vulnerability Overview
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.2 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.
Technical Analysis
REMEDIATION: Update to version 3.2.3, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C