CVE-2026-92994 PUBLISHED

Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API

Assigner: WPScan
Reserved: 17.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.

Product Status

Vendor Unknown
Product Verge3D Publishing and E-Commerce
Versions Default: unaffected
  • affected from 0 to 4.13.1 (excl.)

Credits

  • Raphael P. Cigana finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE