
CVE-2025-12451 The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 4.0 due to insuffici… https://www.cve.org/CVERecord?id=CVE-2025-12451
Post summary
The post announces a stored XSS flaw in the Easy SVG Support WordPress plugin (v4.0 and earlier) caused by insufficient sanitization of SVG uploads, with no PoC, exploit, patch, or active exploitation details provided.
