Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9487

Опубликовано: 22 сент. 2025
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads

EPSS

Процентиль: 22%
0.00073
Низкий

4.7 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.7
github
5 месяцев назад

The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads

EPSS

Процентиль: 22%
0.00073
Низкий

4.7 Medium

CVSS3

Дефекты