CVE-2026-92994
Received Received - Intake

Verified Cross-Site Scripting in Verge3D WordPress Plugin

Vulnerability report for CVE-2026-92994, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
verge3d verge3d to 4.13.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated stored cross-site scripting (XSS) vulnerability in the Verge3D Publishing and E-Commerce WordPress plugin before version 4.13.1. The plugin does not validate file contents uploaded through its storage feature, serving them back with an attacker-controlled content type. This allows attackers to upload a file containing malicious JavaScript that executes in the browser of any user who views it.

Detection Guidance

Check if the Verge3D plugin version is below 4.13.1. Use commands like 'wp plugin list' in WordPress or inspect the plugin directory for version details. Look for unexpected JavaScript files in the file storage feature.

Impact Analysis

An attacker could exploit this to steal user sessions, perform actions on behalf of users, or deliver malware. Any user viewing the malicious file would have their browser execute the attacker's JavaScript code without needing authentication.

Compliance Impact

This vulnerability could lead to data breaches, exposing personal or sensitive data, which may violate GDPR and HIPAA compliance. Organizations using the vulnerable plugin may face legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update the Verge3D plugin to version 4.13.1 or later immediately. Remove any suspicious files from the file storage feature. Monitor network traffic for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92994. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart