PT-2026-69173 · WordPress · Ymc Filter
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YMC Filter versions prior to 3.12.9
Description
The plugin fails to sanitize SVG files uploaded through an icon upload feature. This allows users with the Author role or higher to upload a file containing JavaScript, leading to Stored Cross-Site Scripting (XSS), where the script executes in the site's origin when the file is viewed.
Recommendations
Update YMC Filter to version 3.12.9 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ymc Filter