GoodLayers Core WordPress Plugin SVG Upload Vulnerability Allowing Malicious Payloads

Vulnerability

A vulnerability exists in the GoodLayers Core WordPress plugin in versions prior to 2.1.3. It allows users with a subscriber role and above to upload SVG files containing malicious payloads. This could lead to stored cross-site scripting (XSS) vulnerabilities, as the uploaded SVGs could be used to execute scripts in the context of the user viewing the content.

Impact

Exploitation of this vulnerability could lead to stored cross-site scripting, where uploaded SVGs are used to execute malicious scripts.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.6
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.