Source: National Vulnerability Database

The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-1562

91 hits since 2022-06-01

PHP Vulns Source Ratio: 17% (6806 total, 571 propagated, 3403 filtered)