CVE-2026-16559
YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.
| Vendor | unknown |
| Product | ymc filter |
| Published | Aug 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ymc filter
Be the first to know when new unknown vulnerabilities affecting unknown ymc filter are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / YMC Filter
0 < 3.12.9
References
Credits
Artus KG WPScan