---
id: CVE-2026-92994
title: >-
  The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not
  validate the contents of files uploaded through its file storage feature and
  serves them back with an attacker-controlled content type, allowing
  unauthenticate…
summary: >-
  The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not
  validate the contents of files uploaded through its file storage feature and
  serves them back with an attacker-controlled content type, allowing
  unauthenticate…
severity: none
cwe:
  - CWE-79
product: Verge3D Publishing and E-Commerce
affected:
  - verge3d_publishing_and_e-commerce < 4.13.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:09.983'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92994'
references:
  - url: 'https://wpscan.com/vulnerability/48356bf5-634f-4008-8904-10ab35007e21/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.558Z'
---

## Overview

The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
