CVE-2026-92994
Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
| Vendor | unknown |
| Product | verge3d publishing and e-commerce |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown verge3d publishing and e-commerce
Be the first to know when new unknown vulnerabilities affecting unknown verge3d publishing and e-commerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Verge3D Publishing and E-Commerce
0 < 4.13.1
References
Credits
Raphael P. Cigana WPScan