Description
The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.7 due to insufficient sanitization of SVG files. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
* (semver)
Timeline
| 2025-12-05: | Vendor Notified |
| 2026-01-05: | Disclosed |
Credits
Sirati Hiranthani
References
www.wordfence.com/...-9624-4924-92e8-adb61356aecb?source=cve
plugins.trac.wordpress.org/...r/trunk/url-image-importer.php
plugins.trac.wordpress.org/...s/1.0.7/url-image-importer.php
plugins.trac.wordpress.org/...importer&sfp_email=&sfph_mail=