CVE-2026-94672
Received Received - Intake

Insecure Direct Object Reference (IDOR) in Safe SVG <= 2.5.0

Vulnerability report for CVE-2026-94672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Patchstack

Description

Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
patchstack safe_svg to 2.5.0 (inc)
patchstack safe_svg to 2.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object References (IDOR) issue in the WordPress Safe SVG plugin versions 2.5.0 and below. It allows attackers with contributor-level access to manipulate IDs in URLs to access unauthorized data.

Detection Guidance

To detect this IDOR vulnerability in Safe SVG <= 2.5.0, check plugin versions via WordPress admin panel or run commands like 'wp plugin list' in CLI. Look for Safe SVG versions 2.5.0 or below. Inspect server logs for unusual URL patterns with manipulated IDs.

Impact Analysis

An attacker could exploit this to access sensitive data they are not authorized to view, potentially leading to data leaks or unauthorized modifications within the WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized data access, which may violate compliance requirements under GDPR or HIPAA if sensitive user data is exposed. Organizations must address it to maintain regulatory compliance.

Mitigation Strategies

Immediately update Safe SVG to version 2.5.1 or later. Enable auto-updates for plugins if using Patchstack. Remove contributor-level access for untrusted users until patched. Monitor for unauthorized data access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart