CyberRota Analysis
AI-GeneratedThe YMC Filter WordPress plugin prior to version 3.12.9 is vulnerable due to inadequate sanitization of SVG files, allowing low-privileged users to upload malicious JavaScript. This can lead to cross-site scripting (XSS) attacks, compromising the integrity of the site when the infected file is accessed. WordPress site administrators, especially those using this plugin, should prioritize updating to the latest version to mitigate potential security risks.
Original NVD Description
The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.