CVE-2024-4759: Staude Mime Types Extended
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
Affected products
- Staude Mime Types Extended: up to and including 0.11
Published 2024-06-25. Last modified 2026-06-17.