Vulnerability Description
The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.
References
FAQ
What is CVE-2026-16558?
CVE-2026-16558 is a documented vulnerability. The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is ...
How severe is CVE-2026-16558?
CVSS scoring is not yet available for CVE-2026-16558. Check NVD for updates.
Is there a patch for CVE-2026-16558?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.