Security research The WordPress SVG Security Gap Nobody Is Incentivized to Report
An SVG is not just an image. It is an XML document that can carry scripts. WordPress has no Core sanitizer, plugins enable uploads anyway, and the reporting programs that would flag it consider the whole class out of scope.
Read the article