CVE-2026-16559: YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16559?
CVE-2026-16559 has a risk score of 52, indicating a moderate severity level.
How do I fix CVE-2026-16559?
To fix CVE-2026-16559, update the YMC Filter plugin to version 3.12.9 or later, which includes a patch for this vulnerability.
What types of attacks are possible with CVE-2026-16559?
CVE-2026-16559 allows for Stored XSS attacks by enabling users to upload malicious SVG files that execute JavaScript in the site's context.
Which user roles are affected by CVE-2026-16559?
CVE-2026-16559 affects low-privileged users with the Author role and above, allowing them to exploit the vulnerability.
Is CVE-2026-16559 a common vulnerability in WordPress plugins?
While CVE-2026-16559 is a specific vulnerability in the YMC Filter plugin, unvalidated file uploads are a common security risk in WordPress plugins.