---
id: CVE-2026-16558
title: >-
  The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a
  layout builder setting before outputting it on a public endpoint, and does not
  verify object ownership when the setting is saved, allowing users with the
  Contri…
summary: >-
  The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a
  layout builder setting before outputting it on a public endpoint, and does not
  verify object ownership when the setting is saved, allowing users with the
  Contri…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16558'
references:
  - url: 'https://wpscan.com/vulnerability/06ba0551-deab-41fb-b501-eef0727b431a/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00129
epssPercentile: 0.02913
ingestedAt: '2026-08-09T03:32:40.303Z'
---

## Overview

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
