The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc.php when such uploads are enabled, which could allow users to upload a malicious SVG containing XSS payloads
https://wpscan.com/vulnerability/b957b7c4-7a7c-497e-b8e4-499c821fb1b0/