---
id: CVE-2026-16559
title: >-
  The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files
  uploaded through one of its icon upload features and permits their upload by
  low-privileged users, allowing users with the Author role and above to upload
  a file c…
summary: >-
  The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files
  uploaded through one of its icon upload features and permits their upload by
  low-privileged users, allowing users with the Author role and above to upload
  a file c…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16559'
references:
  - url: 'https://wpscan.com/vulnerability/9b8d265a-542f-4e1b-966d-3fc3dbf7a800/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00431
epssPercentile: 0.34617
ingestedAt: '2026-08-09T03:32:40.334Z'
---

## Overview

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
