2024-05-26 14:27:05 +02:00
### [CVE-2019-18854](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18854)



### Description
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '< use ... xlink:href = " #identifier " > ' substring.
### POC
#### Reference
- https://fortiguard.com/zeroday/FG-VD-19-113
2024-06-09 00:33:16 +00:00
- https://fortiguard.com/zeroday/FG-VD-19-113
2024-05-26 14:27:05 +02:00
- https://wordpress.org/plugins/safe-svg/#developers
2024-06-09 00:33:16 +00:00
- https://wordpress.org/plugins/safe-svg/#developers
2024-05-26 14:27:05 +02:00
- https://wpvulndb.com/vulnerabilities/9937
2024-06-09 00:33:16 +00:00
- https://wpvulndb.com/vulnerabilities/9937
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.