WordPress Plugin Vulnerabilities

Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API

Description

The plugin does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.

Proof of Concept

Affects Plugins

Fixed in 4.13.1

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Raphael P. Cigana
Submitter
Raphael P. Cigana
Verified
Yes

Timeline

Publicly Published
2026-09-28 (about 2 days ago)
Added
2026-09-28 (about 1 day ago)
Last Updated
2026-09-29 (about 9 hours ago)

Other