WordPress Plugin Vulnerabilities

YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload

Description

The plugin does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

Proof of Concept

Affects Plugins

Fixed in 3.12.9

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 27 days ago)
Added
2026-08-03 (about 26 days ago)
Last Updated
2026-08-03 (about 26 days ago)

Other