
CVE-2026-13340 The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves th… https://www.cve.org/CVERecord?id=CVE-2026-13340
Post summary
The text announces a vulnerability in the SVG Support WordPress plugin where .svgz uploads bypass sanitisation, potentially leading to exploitation.

