CVE-2026-16559 - YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
CVE ID :CVE-2026-16559
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...