CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-08 07:17

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16558

Mitre link : CVE-2026-16558

CVE.ORG link : CVE-2026-16558


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')