CVE-2019-18854: 10up Safe Svg

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.

Affected products

  • 10up Safe Svg: up to and including 1.9.4

Published 2019-11-11. Last modified 2026-06-17.