
Enable SVG, WebP, and ICO Upload Security & Risk Analysis
wordpress.org/plugins/enable-svg-webp-ico-uploadThis plugin will enable uploading SVG, WebP & ICO image files to WordPress sites.
Is Enable SVG, WebP, and ICO Upload Safe to Use in 2026?
Generally Safe
Score 91/100Enable SVG, WebP, and ICO Upload has a strong security track record. Known vulnerabilities have been patched promptly.
The "enable-svg-webp-ico-upload" plugin version 1.1.4 presents a mixed security profile. While the code analysis shows good practices in terms of SQL query sanitization and output escaping, with 100% of both being handled correctly, there are significant concerns regarding its attack surface and historical vulnerability record. The plugin exposes two AJAX handlers, both of which lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, posing a direct risk if they are not properly secured within the code itself.
The vulnerability history is particularly concerning, with a total of 5 known CVEs, including 2 high and 2 medium severity vulnerabilities. The common types of vulnerabilities, such as Unrestricted Upload of File with Dangerous Type and Cross-site Scripting, align with potential risks introduced by handling file uploads and user input, which this plugin likely does. The fact that the last vulnerability was recently discovered (2025-11-17) suggests ongoing security issues.
While the absence of critical taint flows and the use of prepared statements are positive indicators, the unprotected AJAX endpoints combined with the plugin's past security incidents create a notable risk. The plugin's strengths lie in its internal code handling of SQL and output, but the external attack vectors and historical issues warrant caution.
Key Concerns
- Unprotected AJAX handlers
- Multiple past high severity CVEs
- Multiple past medium severity CVEs
- Past low severity CVE
- Vulnerability history including XSS
- Vulnerability history including Unrestricted Upload
Enable SVG, WebP, and ICO Upload Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Enable SVG, WebP, and ICO Upload <= 1.1.3 - Authenticated (Author+) Arbitrary File Upload via ICO Upload Bypass
Enable SVG, WebP, and ICO Upload <= 1.1.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploads
Enable SVG, WebP & ICO Upload <= 1.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG
Enable SVG, WebP & ICO Upload <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting
Enable SVG, WebP & ICO Upload <= 1.1.0 - Arbitrary File Upload
Enable SVG, WebP, and ICO Upload Code Analysis
Output Escaping
Enable SVG, WebP, and ICO Upload Attack Surface
AJAX Handlers 2
WordPress Hooks 24
Maintenance & Trust
Enable SVG, WebP, and ICO Upload Maintenance & Trust
Maintenance Signals
Community Trust
Enable SVG, WebP, and ICO Upload Alternatives
WebP Conversion
webp-conversion
Convert your .png and .jpeg images to WebP format for FREE – with absolutely NO limits or hidden restrictions.
SVG Block
svg-block
Display an SVG image as a block, which can be used for displaying images, icons, dividers, buttons
Image Optimizer – Optimize Images and Convert to WebP or AVIF
image-optimization
Automatically resize, optimize, and convert images to WebP and AVIF. Compress images in bulk or on upload to boost your WordPress site performance.
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN
wp-smushit
Optimize and compress images with lossless and lossy compression, lazy load, WebP & AVIF conversion, and global image CDN.
Enable SVG, WebP, and ICO Upload Developer Profile
5 plugins · 13K total installs
How We Detect Enable SVG, WebP, and ICO Upload
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enable-svg-webp-ico-upload/admin/css/itc-admin.css/wp-content/plugins/enable-svg-webp-ico-upload/admin/js/itc-admin.js/wp-content/plugins/enable-svg-webp-ico-upload/admin/js/itc-admin.jsenable-svg-webp-ico-upload/admin/css/itc-admin.css?ver=enable-svg-webp-ico-upload/admin/js/itc-admin.js?ver=HTML / DOM Fingerprints
ITC_SVG_Upload_Admin