
CVE-2026-16559 The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged … https://www.cve.org/CVERecord?id=CVE-2026-16559
Post summary
The text announces a persistence vulnerability in the YMC Filter WordPress plugin where unsanitized SVG uploads are allowed by low-privilege users, but no PoC, exploit, or patch information is provided.


