๐Ÿ” CVE Alert

CVE-2026-16559

UNKNOWN 0.0

YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

Vendor unknown
Product ymc filter
Published Aug 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ymc filter

Be the first to know when new unknown vulnerabilities affecting unknown ymc filter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / YMC Filter
0 < 3.12.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9b8d265a-542f-4e1b-966d-3fc3dbf7a800/

Credits

Artus KG WPScan