CVE-2026-92994: Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Any site running the affected Verge3D Publishing and E-Commerce WordPress plugin with its file storage feature reachable by attackers is exposed. An attacker does not need to authenticate before uploading the malicious file.
What must happen for the stored script to execute?
A user must open the attacker-uploaded file in a browser. The file is served with an attacker-controlled content type, which allows malicious JavaScript in the stored file to execute.
Which versions are affected?
Versions before 4.13.1 are affected. Updating to version 4.13.1 or later addresses the affected version range described here.