YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.8epss 0.2%
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
Unknown · YMC Filterpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/9b8d265a-542f-4e1b-966d-3fc3dbf7a800/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.