CVE-2026-16559Disclosure

LOWCVSS 6.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 308-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-16559 The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged … https://www.cve.org/CVERecord?id=CVE-2026-16559

    Post summary

    The text announces a persistence vulnerability in the YMC Filter WordPress plugin where unsanitized SVG uploads are allowed by low-privilege users, but no PoC, exploit, or patch information is provided.

    000011.5K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16559 The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged … https://www.cve.org/CVERecord?id=CVE-2026-16559 ----- Traducción: CVE-2026-16559 El … http://infoflow.cloud`

    Post summary

    The message announces CVE‑2026‑16559, detailing that the YMC Filter WordPress plugin versions prior to 3.12.9 allow low‑privileged users to upload unsanitized SVG files, potentially leading to malicious exploitation.

    00000165
    98 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🖼️ WordPress SVG upload issue enables stored JavaScript CVE-2026-16559 affects the YMC Filter WordPress plugin before 3.12.9. The plugin fails to properly sanitize SVG uploads, potentially allowing users with Author privileges or higher to upload SVG files containing JavaScript that executes when viewed. 🔎 Source: WPScan / CVE disclosure #XSS #WordPress #CVE #AppSec #CyberSecurity

    Post summary

    The text announces a stored XSS vulnerability (CVE-2026-16559) in the YMC Filter WordPress plugin, detailing the flaw without providing exploitation, remediation, or PoC references.

    0000039
    34 followersView on X

Explore more