PT-2026-69173 · WordPress · Ymc Filter

·

CVE-2026-16559

·

Published

2026-08-08

·

Updated

2026-08-11

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YMC Filter versions prior to 3.12.9
Description The plugin fails to sanitize SVG files uploaded through an icon upload feature. This allows users with the Author role or higher to upload a file containing JavaScript, leading to Stored Cross-Site Scripting (XSS), where the script executes in the site's origin when the file is viewed.
Recommendations Update YMC Filter to version 3.12.9 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16559

Affected Products

Ymc Filter