Junglewise Threat Intelligence

CVE-2026-48973: Benbodhi SVG Support missing authorization in access control

CVE-2026-48973 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Executive brief

The SVG Support plugin for WordPress, which allows users to upload and manage Scalable Vector Graphics, contains a security flaw in its access control settings. An authenticated user with low-level permissions, such as a Contributor, can bypass intended restrictions to perform actions they should not be authorized to do. This could allow unauthorized changes to site settings or content management features, potentially compromising the integrity of the website.

Technical details

A missing authorization (CWE-862) vulnerability exists in the Benbodhi SVG Support plugin for WordPress through version 2.5.14. The flaw resides in the plugin's failure to properly validate user permissions before executing certain administrative or configuration functions. An attacker authenticated with low-level privileges (Contributor level) can exploit this over a network to bypass access control security levels and perform unauthorized actions. While the impact is primarily limited to integrity, it allows for the manipulation of plugin-specific settings. As of the advisory date, no official patch has been released.

Affected products

  • Benbodhi SVG Support n/a through 2.5.14

Timeline

  • 2026-01-09: disclosed: Reported by Steven Julian
  • 2026-05-27: advisory: Published by Patchstack and NVD

References