NONE · 0

CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Aut...

Vulnerability Description

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

References

FAQ

What is CVE-2026-16559?

CVE-2026-16559 is a documented vulnerability. The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Aut...

How severe is CVE-2026-16559?

CVSS scoring is not yet available for CVE-2026-16559. Check NVD for updates.

Is there a patch for CVE-2026-16559?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.