OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92994

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Verge3D Publishing and E-Commerce WordPress plugin prior to version 4.13.1 is vulnerable due to inadequate validation of uploaded files, enabling unauthenticated attackers to upload malicious JavaScript files. This vulnerability can lead to cross-site scripting (XSS) attacks, affecting any user who accesses the compromised files in their browser. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-92994
Severity
HIGH
CVSS
8.8
EPSS
0.28%
WordPress Java

Original NVD Description

The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.