CVE-2026-16558
Received Received - Intake

YMC Filter WordPress Plugin Stored Cross-Site Scripting

Vulnerability report for CVE-2026-16558, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ymc_filter ymc_filter to 3.12.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the YMC Filter WordPress plugin before version 3.12.8. Users with the Contributor role or higher can inject malicious JavaScript via the Layout Builder Schema. The plugin fails to sanitize input before displaying it on a public endpoint and does not verify object ownership when saving settings. The injected script executes in browsers of visitors viewing affected filters.

Detection Guidance

Check if the YMC Filter WordPress plugin version is below 3.12.8. Inspect the Layout Builder Schema settings for any injected JavaScript code. Review public endpoints for unexpected script execution.

Impact Analysis

Attackers could steal user sessions, redirect visitors to malicious sites, or perform actions on their behalf. Visitors to your WordPress site may have their data compromised if they view a page with an affected filter.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting user data. It may result in unauthorized access to personal or health information, leading to legal penalties and reputational damage.

Mitigation Strategies

Update the YMC Filter plugin to version 3.12.8 or later immediately. Remove any suspicious JavaScript code from the Layout Builder Schema settings. Restrict Contributor role permissions if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16558. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart