What is CVE-2026-16559?
The CVE-2026-16559 vulnerability affects YMC Filter WordPress plugin versions before 3.12.9. It allows low-privileged users (Author role and above) to upload unsanitized SVG files containing JavaScript, leading to Stored XSS attacks that execute in the site's origin. Plugin should be immediately updated to the latest version.
Azərbaycanca: CVE-2026-16559 zəifliyi YMC Filter WordPress plagininin 3.12.9-dan əvvəlki versiyalarında aşkar edilib. Bu, aşağı səlahiyyətli istifadəçilərə (Author rolu və yuxarısı) təmizlənməmiş SVG faylları yükləməyə imkan verir ki, bu da sayt mənşəyində JavaScript-in icrası ilə nəticələnən Stored XSS hücumuna səbəb ola bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the YMC Filter plugin are affected by CVE-2026-16559?
The CVE-2026-16559 vulnerability affects YMC Filter WordPress plugin versions before 3.12.9.
What can an attacker achieve by exploiting CVE-2026-16559?
A low-privileged user can upload unsanitized SVG files, leading to Stored XSS attacks that execute JavaScript in the site's origin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.