Support SVG – Upload svg files in wordpress without hassle Security & Risk Analysis

wordpress.org/plugins/support-svg

This plugin will help you to upload svg format image in WordPress media library regardless of the theme. That is, it works with every theme.

20 active installs v1.1.3 PHP 7.4+ WP 5.0+ Updated Jan 20, 2026
sanitizesecuritysvguploadvector
99
A · Safe
CVEs total2
Unpatched0
Last CVENov 25, 2024
Safety Verdict

Is Support SVG – Upload svg files in wordpress without hassle Safe to Use in 2026?

Generally Safe

Score 99/100

Support SVG – Upload svg files in wordpress without hassle has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Nov 25, 2024Updated 3mo ago
Risk Assessment

The "support-svg" plugin v1.1.3 demonstrates a generally strong security posture in its static analysis. It adheres to best practices by utilizing prepared statements for all SQL queries, ensuring proper output escaping, and having no identified critical or high severity taint flows. The absence of a significant attack surface with unprotected entry points is also a positive indicator. However, the plugin's vulnerability history is a significant concern. With two known medium severity CVEs, both related to Cross-Site Scripting (XSS), the plugin has shown a pattern of introducing vulnerabilities that could allow for malicious code injection. The fact that the last vulnerability was relatively recent (November 2024) and is currently unpatched, despite the version number being higher, suggests a potential ongoing issue with code quality or a lack of timely security updates.

While the current static analysis is clean, the historical vulnerability data strongly suggests that this plugin should be treated with caution. The two medium severity XSS vulnerabilities indicate a recurring weakness in input sanitization or output encoding, which could be present in subtle ways not caught by the current static analysis or that have been fixed in this specific version but indicate a higher likelihood of future issues. The absence of capability checks and nonce checks on potential AJAX or REST API endpoints (though none are currently identified) leaves a theoretical gap for future vulnerabilities if these features are added without proper security controls. Therefore, despite the promising static analysis, the plugin's past security record necessitates a degree of skepticism and careful monitoring.

Key Concerns

  • Two medium severity XSS vulnerabilities in history
  • Historically prone to XSS, lack of recent patch
  • No capability checks
  • No nonce checks
Vulnerabilities
2 published

Support SVG – Upload svg files in wordpress without hassle Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-11091medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Support SVG – Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload

Nov 25, 2024 Patched in 1.1.1 (1d)
CVE-2024-4272medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Support SVG <= 1.0.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG

Jun 22, 2024 Patched in 1.1.0 (6d)
Version History

Support SVG – Upload svg files in wordpress without hassle Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Support SVG – Upload svg files in wordpress without hassle Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0
Attack Surface

Support SVG – Upload svg files in wordpress without hassle Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\SupportSvg.php:24
filterupload_mimesincludes\SupportSvg.php:42
filterwp_handle_sideload_prefilterincludes\SupportSvg.php:43
filterwp_handle_upload_prefilterincludes\SupportSvg.php:44
filterwp_check_filetype_and_extincludes\SupportSvg.php:45
actionadmin_headincludes\SupportSvg.php:47
Maintenance & Trust

Support SVG – Upload svg files in wordpress without hassle Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 20, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Support SVG – Upload svg files in wordpress without hassle Developer Profile

Sayedul Sayem

4 plugins · 10K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect Support SVG – Upload svg files in wordpress without hassle

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/support-svg/assets/css/admin.css/wp-content/plugins/support-svg/assets/js/admin.js
Script Paths
/wp-content/plugins/support-svg/assets/js/admin.js
Version Parameters
support-svg/assets/css/admin.css?ver=support-svg/assets/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Support SVG – Upload svg files in wordpress without hassle