CVE-2026-94672: WordPress Safe SVG plugin <= 2.5.0 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 30, 2026
·Updated
Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.
Affected Software
1 affected component
WordPress Safe SVG<=2.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Safe SVG pluginto a version that resolves this vulnerability.Fixed in 2.5.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The vulnerability requires contributor-level privileges. It is remotely reachable and does not require user interaction.
2
What is the documented security impact?
The published vector indicates low confidentiality impact, with no integrity or availability impact listed.