New to Translating WordPress? Read through our Translator Handbook to get started. Hide
| Prio | Original string | Translation | — |
|---|---|---|---|
| ↑ | Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website. | You have to log in to add a translation. | Details |
Original untranslated
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
You have to log in to edit this translation. |
|||
| ↑ | Safe SVG | You have to log in to add a translation. | Details |
Original untranslated |
|||
| Please report security bugs found in the source code of the Safe SVG plugin through the <a href="https://patchstack.com/database/vdp/9e5fb4ed-587a-4ada-8dc3-a5b7362c0501">Patchstack Vulnerability Disclosure Program</a>. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin. | You have to log in to add a translation. | Details | |
Original untranslated
Please report security bugs found in the source code of the Safe SVG plugin through the <a href="https://patchstack.com/database/vdp/9e5fb4ed-587a-4ada-8dc3-a5b7362c0501">Patchstack Vulnerability Disclosure Program</a>. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they're safe. | You have to log in to add a translation. | Details | |
Original untranslated
This is a deliberate design decision: Safe SVG prioritizes guaranteed sanitization over broad compatibility. SVGs are only allowed when we can ensure they're safe.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Globally enabling the <code>image/svg+xml</code> MIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded. | You have to log in to add a translation. | Details | |
Original untranslated
Globally enabling the <code>image/svg+xml</code> MIME type would allow SVGs through all upload paths—including custom ones Safe SVG cannot intercept and sanitize. This would create security vulnerabilities where unsanitized SVGs containing malicious scripts could be uploaded.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like <code>wp_handle_upload()</code> (which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress's underlying <code>_wp_handle_upload()</code> function with arbitrary action parameters. | You have to log in to add a translation. | Details | |
Original untranslated
Safe SVG only allows SVGs through upload paths it can actively sanitize. While most WordPress uploads use standard functions like <code>wp_handle_upload()</code> (which Safe SVG hooks), plugins and themes can create custom upload paths by calling WordPress's underlying <code>_wp_handle_upload()</code> function with arbitrary action parameters.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| To turn isolation off, at the cost of allowing an SVG's CSS to affect the rest of the page: | You have to log in to add a translation. | Details | |
Original untranslated
To turn isolation off, at the cost of allowing an SVG's CSS to affect the rest of the page:
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Inherited properties still cross the boundary, so setting <code>color</code> on an ancestor and using <code>currentColor</code> inside the SVG works, as do CSS custom properties. SVGs that do not contain a <code><style></code> element are rendered without the shadow root and can be styled by theme stylesheets. | You have to log in to add a translation. | Details | |
Original untranslated
Inherited properties still cross the boundary, so setting <code>color</code> on an ancestor and using <code>currentColor</code> inside the SVG works, as do CSS custom properties. SVGs that do not contain a <code><style></code> element are rendered without the shadow root and can be styled by theme stylesheets.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Mostly, yes. The Inline SVG block renders an SVG that carries its own <code><style></code> element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as <code>.entry-content svg { fill: red; }</code> will not apply to those SVGs. | You have to log in to add a translation. | Details | |
Original untranslated
Mostly, yes. The Inline SVG block renders an SVG that carries its own <code><style></code> element inside a shadow root, because CSS inside an inline SVG is otherwise applied to the whole page rather than just the SVG. Stylesheets cannot reach into a shadow root, so theme CSS such as <code>.entry-content svg { fill: red; }</code> will not apply to those SVGs.
CommentFound in faq paragraph. You have to log in to edit this translation. |
|||
| Where do I report security bugs found in this plugin? | You have to log in to add a translation. | Details | |
Original untranslated
Where do I report security bugs found in this plugin?
CommentFound in faq header. You have to log in to edit this translation. |
|||
| Why doesn't Safe SVG globally enable SVG uploads? | You have to log in to add a translation. | Details | |
Original untranslated
Why doesn't Safe SVG globally enable SVG uploads?
CommentFound in faq header. You have to log in to edit this translation. |
|||
| Can my theme style an inline SVG? | You have to log in to add a translation. | Details | |
Original untranslated
Can my theme style an inline SVG?
CommentFound in faq header. You have to log in to edit this translation. |
|||
| WordPress’s <code>_wp_handle_upload( $file, $action )</code> function allows any <code>$action</code> value, which determines the filter hook name: <code>{$action}_prefilter</code>. Safe SVG hooks common actions like <code>wp_handle_upload</code> and <code>wp_handle_sideload</code>, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths. | You have to log in to add a translation. | Details | |
Original untranslated
WordPress’s <code>_wp_handle_upload( $file, $action )</code> function allows any <code>$action</code> value, which determines the filter hook name: <code>{$action}_prefilter</code>. Safe SVG hooks common actions like <code>wp_handle_upload</code> and <code>wp_handle_sideload</code>, but cannot hook arbitrary custom actions defined by third-party code. Since upload actions are unbounded and MIME allowances are global, we cannot guarantee sanitization coverage across all possible upload paths.
CommentFound in description paragraph. You have to log in to edit this translation. |
|||
| Technical: Upload Path Security | You have to log in to add a translation. | Details | |
Original untranslated
Technical: Upload Path Security
CommentFound in description header. You have to log in to edit this translation. |
|||
| SVG Optimization is done through the following library: <a href="https://github.com/svg/svgo">https://github.com/svg/svgo</a>. | You have to log in to add a translation. | Details | |
Original untranslated
SVG Optimization is done through the following library: <a href="https://github.com/svg/svgo">https://github.com/svg/svgo</a>.
CommentFound in description paragraph. You have to log in to edit this translation. |
|||
Export as
Comment
Short description.