Remote Code Execution Vulnerability in YMC Filter Plugin for WordPress
CVE-2026-16559
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 8 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-16559?
The YMC Filter plugin for WordPress prior to version 3.12.9 is susceptible to an improper input validation vulnerability that fails to sanitize SVG files uploaded via icon upload features. This oversight allows low-privileged users, including those with an Author role, to upload malicious files containing JavaScript code. When these files are accessed, the JavaScript executes within the website's origin, posing a significant threat to site security and potentially allowing unauthorized control over site functionality.
Affected Version(s)
YMC Filter 0 < 3.12.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.