AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16558

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The YMC Filter WordPress plugin prior to version 3.12.8 is vulnerable due to inadequate sanitization and escaping of a layout builder setting, which allows users with Contributor roles and higher to inject malicious JavaScript. This can lead to cross-site scripting (XSS) attacks, potentially compromising the security of visitors' browsers. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16558
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
WordPress Java

Original NVD Description

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.