10up is a web development agency with a focused portfolio of WordPress plugins and tools, including products such as Safe SVG, ElasticPress, Restricted Site Access, and Simple Local Avatars that serve publishing and search optimization use cases. The vulnerabilities affecting this vendor center on application-layer weaknesses typical of web-facing PHP code, including cross-site request forgery, cross-site scripting, authorization bypass, and input-handling flaws that recur across its plugin ecosystem. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 10up over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18855HIGH A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes. | Nov 11, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-18854HIGH A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier"> | Nov 11, 2019 | 7.5 | 25 | NO | NO |
CVE-2024-43116HIGH Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10. | Aug 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-1613MEDIUM The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-b | Sep 26, 2022 | 5.3 | 19 | NO | NO |
CVE-2024-8378MEDIUM The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload | Nov 7, 2024 | 4.8 | 17 | NO | NO |
CVE-2023-48753MEDIUM Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Ac | Jun 4, 2024 | 5.3 | 17 | NO | NO |
CVE-2022-1091MEDIUM The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerabilit | Apr 18, 2022 | 6.1 | 17 | NO | NO |
CVE-2025-8482MEDIUM The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_ | Aug 12, 2025 | 4.3 | 16 | NO | NO |
CVE-2021-4405MEDIUM The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on t | Jul 1, 2023 | 4.3 | 16 | NO | NO |
CVE-2024-10786MEDIUM The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versio | Nov 16, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 10up.
Media articles that mention a CVE ID that affects a product developed by 10up — matched by CVE ID, not by vendor name.