WP SVG Icons <= 3.2.2 - Cross-Site Request Forgery to Remote Code Execution

2019-08-09 00:00
Zeroauth

Strategic Overview

Status
Patched in 3.2.3
Affected PluginWP SVG Icons
Affected Version< 3.2.3
CVSS8.8High
CVECVE-2019-14216
View all WP SVG Icons vulnerabilities

Vulnerability Overview

An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.2 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.

Technical Analysis

REMEDIATION: Update to version 3.2.3, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C