Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 08 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Ymc Filter Ymc Filter ymc Filter |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Ymc Filter Ymc Filter ymc Filter |
Sat, 08 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sat, 08 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed. | |
| Title | YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-11T19:34:57.974Z
Reserved: 2026-07-22T12:09:50.019Z
Link: CVE-2026-16559
Updated: 2026-08-11T19:34:32.455Z
Status : Received
Published: 2026-08-08T07:17:10.237
Modified: 2026-08-11T20:17:28.740
Link: CVE-2026-16559
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:15:07Z