A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Link | Tags |
---|---|
https://wpvulndb.com/vulnerabilities/9937 | third party advisory |
https://fortiguard.com/zeroday/FG-VD-19-113 | third party advisory |
https://plugins.trac.wordpress.org/changeset/2185438 | third party advisory |
https://wordpress.org/plugins/safe-svg/#developers | third party advisory release notes |