CVE-2026-94077: WordPress Safe SVG plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
Affected Software
1 affected component
WordPress Safe SVG<=2.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Safe SVG pluginto a version that resolves this vulnerability.Fixed in 2.5.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users need access for this issue to be exploited?
The vulnerability is described as contributor XSS, so exploitation requires an attacker to have a WordPress Contributor-level account.
2
Does exploitation require user interaction?
Yes. The supplied CVSS vector includes UI:R, indicating that user interaction is required for exploitation.
3
Is the vulnerability remotely reachable?
The CVSS vector lists AV:N, indicating network-accessible attack conditions. It also lists PR:L, so low privileges are required.