NONE · 0

CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is ...

Vulnerability Description

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.

References

FAQ

What is CVE-2026-16558?

CVE-2026-16558 is a documented vulnerability. The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is ...

How severe is CVE-2026-16558?

CVSS scoring is not yet available for CVE-2026-16558. Check NVD for updates.

Is there a patch for CVE-2026-16558?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.