Sceawere

Vulnerability Detail

CVE-2026-94077UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Safe SVG Contributor XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
10up
Product
Safe SVG
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T13:17:23.210Z",
  "pubdate": "2026-09-30T13:17:23.210Z",
  "executiveSummary": "The Safe SVG plugin, in versions 2.5.0 and below, contains a Cross-Site Scripting (XSS) vulnerability that allows authenticated contributors to inject malicious scripts into the application.\nThis vulnerability stems from improper sanitization of SVG files, enabling the execution of arbitrary JavaScript within the context of the victim's browser session.\nImpacted systems include WordPress installations utilizing the Safe SVG plugin.\nThe risk implication is significant, as successful exploitation can lead to unauthorized access to sensitive user data, session hijacking, or administrative account compromise if a privileged user views the malicious SVG.\nThe vulnerability requires authenticated access with contributor-level privileges or higher to successfully upload the malicious SVG file.\nExploitation does not require advanced network positioning, as it relies on the application's ability to render or process user-supplied SVG content.",
  "technicalDetails": "The vulnerability resides within the Safe SVG plugin's file processing logic, which fails to adequately sanitize SVG payloads containing malicious script elements during the upload process.\nScalable Vector Graphics (SVG) files are XML-based and support embedding script tags, event handlers (e.g., onload, onerror), and other active content.\nWhen a contributor-level user uploads a crafted SVG file, the plugin does not effectively strip these executable elements before saving the file to the web server's storage.\nThe attack flow proceeds as follows: First, an attacker creates an SVG file containing a malicious JavaScript payload, such as a script that triggers an XHR request to an attacker-controlled endpoint or redirects the user.\nSecond, the attacker uploads this crafted SVG file to the WordPress media library using their contributor account.\nThird, the attacker ensures the SVG file is viewed by a higher-privileged user, such as an administrator, often through social engineering or by placing the file in a location where it will be rendered in the admin dashboard.\nWhen the victim opens or views the SVG in the browser, the embedded script executes within the security context of the target application.\nBecause the script runs in the context of the victim's browser, the attacker can perform actions on behalf of the victim, including stealing session cookies, modifying site content, or creating new administrative accounts if the victim's permissions allow.\nThe root cause is the plugin's failure to utilize a robust, allow-list-based XML parser capable of detecting and removing non-static elements, such as script tags or attribute-based execution vectors, before the file is finalized.\nThis vulnerability persists in versions 2.5.0 and earlier, indicating that the sanitization routine is insufficient against well-crafted payloads designed to bypass basic filtering mechanisms.\nSuccessful exploitation results in Stored XSS, allowing the attacker to maintain persistence or conduct lateral movement within the application environment, significantly undermining the security posture of the WordPress instance."
}
CVE-2026-94077: Safe SVG Contributor XSS Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere