AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16559

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The YMC Filter WordPress plugin prior to version 3.12.9 is vulnerable due to inadequate sanitization of SVG files, allowing low-privileged users to upload malicious JavaScript. This can lead to cross-site scripting (XSS) attacks, compromising the integrity of the site when the infected file is accessed. WordPress site administrators, especially those using this plugin, should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-16559
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress Java

Original NVD Description

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.