Benbodhi's vulnerability footprint is narrowly centered on its SVG support component, with the durable signal reflecting application-layer input-handling deficiencies around cross-site scripting. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Benbodhi over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4022MEDIUM The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malicious javascript are not sanitized. While version 2.5 adds the | Nov 16, 2022 | 5.4 | 21 | NO | NO |
CVE-2026-48973MEDIUM Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects SVG Support: from n/a throu | May 27, 2026 | 4.3 | 19 | NO | NO |
CVE-2021-24686MEDIUM The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to per | Feb 1, 2022 | 4.8 | 19 | NO | NO |
CVE-2023-6708MEDIUM The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input s | Jul 18, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-10222MEDIUM The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input saniti | Feb 21, 2025 | 5.4 | 17 | NO | NO |
CVE-2022-1755MEDIUM The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting atta | Sep 26, 2022 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Benbodhi.
Media articles that mention a CVE ID that affects a product developed by Benbodhi — matched by CVE ID, not by vendor name.