CVE-2026-16559 PUBLISHED

YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload

Assigner: WPScan
Reserved: 22.07.2026 Published: 08.08.2026 Updated: 08.08.2026

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

Product Status

Vendor Unknown
Product YMC Filter
Versions Default: unaffected
  • affected from 0 to 3.12.9 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE