Impact
The YMC Filter WordPress plugin, in all releases prior to 3.12.9, fails to sanitize SVG files uploaded via its icon upload feature. This oversight allows an authenticated user with the Author role or higher to upload an SVG that contains malicious JavaScript. When a visitor later views the uploaded icon, the script runs in the site’s origin, potentially stealing credentials or performing other unauthorized actions. The weakness is a classic stored cross‑site scripting flaw, which can compromise the confidentiality, integrity, and availability of the site.
Affected Systems
The affected product is the YMC Filter WordPress plugin for sites running WordPress. Versions earlier than 3.12.9 are vulnerable. No additional vendor or version details are available.
Risk and Exploitability
Because the flaw requires only an Author‑level account to upload the file, a single compromised or newly created author account can trigger the vulnerability. The exploitation probability is unknown as EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the low attack effort and the ability to run arbitrary code on the site origin make the risk high.
OpenCVE Enrichment