Sceawere
Vulnerability Detail
CVE-2026-94672UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Safe SVG Contributor IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- 10up
- Product
- Safe SVG
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T13:17:27.140Z",
"pubdate": "2026-09-30T13:17:27.140Z",
"executiveSummary": "The Safe SVG plugin for WordPress, specifically versions up to and including 2.5.0, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis flaw allows authenticated contributors to modify or access SVG files that they should not have permissions to manipulate.\nBy manipulating object references during the file handling process, an attacker can bypass authorization checks, potentially leading to unauthorized modification of server-side resources.\nThe vulnerability affects the security boundaries established for contributor-level users within the WordPress environment.\nThe risk implication involves the potential for integrity loss and unauthorized file manipulation, although the severity is constrained by the requirement for a contributor-level authenticated account.\nSuccessful exploitation allows an attacker to bypass internal access controls, granting them the ability to perform actions on objects (SVG files) that are outside their designated scope of privilege.\nThis vulnerability highlights a failure in the plugin's authorization logic when verifying user ownership or access rights to specific media objects during interaction.",
"technicalDetails": "The vulnerability is rooted in an Insecure Direct Object Reference (IDOR) flaw within the Safe SVG plugin, affecting all versions up to and including 2.5.0.\nAn IDOR occurs when an application exposes a reference to an internal implementation object, such as a file ID or file path, without implementing sufficient authorization checks to verify if the requesting user has the appropriate permissions to perform the requested action on that specific object.\nIn the context of the Safe SVG plugin, the vulnerable component manages the upload, processing, and retrieval of SVG files. When a user with the contributor role interacts with the plugin's functionality, the application fails to adequately validate whether the authenticated user possesses the necessary privileges to modify or manage a specific SVG object identified by the application.\nThe attack flow begins with an authenticated contributor identifying a target SVG file managed by the plugin. The attacker then intercepts or crafts a request—typically involving a POST or GET request that references the target file's unique ID or path—and submits it to the server. Because the plugin lacks proper server-side authorization checks for these specific object requests, it processes the command as if the user were authorized.\nThe root cause lies in the application's failure to perform a strict mapping between the requested object identifier and the current user's session credentials. Instead of validating that the user is the owner or holds the required administrative role for the specific file, the plugin relies on implicit trust based on the user's general authentication status.\nAs a result, a contributor can potentially perform operations such as unauthorized modification, deletion, or renaming of SVG assets that were uploaded by other users or administrators. This capability violates the principle of least privilege, as the contributor's access is scoped beyond their intended operational boundaries.\nThe post-exploitation impact includes the loss of data integrity for media assets stored within the plugin's jurisdiction. Furthermore, since SVG files are XML-based, successful unauthorized modification could potentially be leveraged in chaining attacks if other vulnerabilities or misconfigurations exist, such as cross-site scripting (XSS) if the SVG file processing lacks strict sanitization during retrieval or if the attacker can inject malicious XML content into the modified file."
}