๐Ÿ” CVE Alert

CVE-2026-92994

UNKNOWN 0.0

Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.

Vendor unknown
Product verge3d publishing and e-commerce
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown verge3d publishing and e-commerce

Be the first to know when new unknown vulnerabilities affecting unknown verge3d publishing and e-commerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Verge3D Publishing and E-Commerce
0 < 4.13.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/48356bf5-634f-4008-8904-10ab35007e21/

Credits

Raphael P. Cigana WPScan