Viable URL Media Uploader Plugin Vulnerability (CVE-2025-14564)

On this page

Security Alert Summary

The Viable URL Media Uploader WordPress plugin contains a stored cross-site scripting (XSS) vulnerability via SVG file uploads in all versions up to and including 1.0.0. Authenticated users with Author-level access and above can inject scripts into uploaded SVG files that execute when other users access those files, due to insufficient input sanitization and output escaping.


CVE Details

  • CVE ID: CVE-2025-14564
  • Affected component: Viable URL Media Uploader plugin for WordPress
  • Affected versions: All versions up to and including 1.0.0
  • Published: September 30, 2026 at 09:17:11 AM
  • Last modified: September 30, 2026 at 04:16:55 PM
  • CVSS v3.1: Base Score 6.4, MEDIUM — Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
  • Authentication/Privileges/User Interaction: Requires an authenticated user with low privileges (Author-level or higher). No user interaction is required for exploitation once a malicious SVG is uploaded.
  • Primary impact: Confidentiality – Low; Integrity – Low; Availability – None
  • Scope: Changed
  • Weakness: CWE-79 (Improper Neutralization of Input During Web Page Generation)

Technical Details

The vulnerability is a stored Cross-Site Scripting (XSS) issue that occurs when SVG files uploaded through the plugin are not properly sanitized or escaped on output. An authenticated user with Author-level access can upload a crafted SVG containing arbitrary JavaScript. When another user views or accesses the SVG file, the embedded script can execute in the context of that user’s browser.

The provided references point to the plugin code handling SVG support (class-vumu-svg-support.php), indicating the component responsible for processing SVG uploads. The root cause is insufficient input sanitization and missing output escaping for uploaded SVG content, allowing executable script content to be stored and served.

Impact is limited to what JavaScript running in a victim’s browser can accomplish. Given the CVSS impacts, exploitation may allow limited disclosure or alteration of data accessible to the victim and enable actions the victim can perform in their session, but does not indicate direct server compromise or availability impact.


How This Could Impact Your Website

Consider a site with multiple WordPress users: a site owner who manages plugins, internal staff who create content, and an external contractor or contributor who has Author-level access to upload media. If a contributor or contractor uploads a malicious SVG, any staff member or visitor who accesses that SVG could have a script execute in their browser. Practical consequences include exposure of data visible to the user (for example, email addresses shown in the admin UI), session data accessible in the browser, or actions performed on behalf of the user within the constraints of their privileges.

This increases the risk of targeted phishing or social engineering that leverages information gathered via a successful XSS exploit. If you’re unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review your setup.


Recommended Actions

  • Update the affected plugin as soon as a patched version is available.
  • Review and reduce unnecessary user roles, especially contributor and Author-level accounts.
  • Enforce strong passwords and two-factor authentication for editors and administrators.
  • Remove unused or unmaintained plugins from your site.
  • Monitor site activity and logs for unusual behavior related to media uploads and user actions.

If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.


References