๐Ÿ” CVE Alert

CVE-2026-16558

UNKNOWN 0.0

YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.

Vendor unknown
Product ymc filter
Published Aug 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ymc filter

Be the first to know when new unknown vulnerabilities affecting unknown ymc filter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / YMC Filter
3.6.0 < 3.12.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/06ba0551-deab-41fb-b501-eef0727b431a/

Credits

Usama Arshad WPScan