Vulnerability Details CVE-2024-10482
The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-10482
-
cpe:2.3:a:wptinysolutions:media_library_tools:1.0.0
-
cpe:2.3:a:wptinysolutions:media_library_tools:1.1.4