What is CVE-2026-16558?
The YMC Filter WordPress plugin before version 3.12.8 does not sanitize a layout builder setting and lacks object ownership verification. This allows users with the Contributor role and above to inject stored JavaScript, which can execute in other users' browsers. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: YMC Filter WordPress plaginin 3.12.8-dən əvvəlki versiyalarında layout builder parametri sanitizə olunmur və obyekt sahibliyi yoxlanılmır. Bu, Contributor və daha yuxarı roluna malik istifadəçilərə JavaScript kodu yerləşdirməyə imkan verir ki, bu da digər istifadəçilərin brauzerində icra oluna bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the YMC Filter plugin are affected by CVE-2026-16558?
CVE-2026-16558 affects versions of the YMC Filter WordPress plugin prior to 3.12.8.
What role level is required to exploit CVE-2026-16558?
Exploiting this vulnerability requires at least the Contributor role or a higher role level.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.