Description
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 fails to validate the contents of files uploaded through its file storage feature and serves them back with an attacker‑controlled content type. This allows an unauthenticated attacker to store a file containing malicious JavaScript that executes in the browser of any user who opens it. The flaw is a classic example of a stored cross‑site scripting vulnerability (CWE‑79) that can lead to unauthorized execution of arbitrary code in the context of the victim’s browser, resulting in potential theft of session cookies, defacement, or further credential compromise.

Affected Systems

Any installation of the Verge3D Publishing and E-Commerce WordPress plugin with a version earlier than 4.13.1 is affected. The vulnerability exists in the plugin’s file storage API and is independent of the host WordPress version or other plugins.

Risk and Exploitability

The flaw is exploitable by any user with access to the web interface that accepts file uploads, and does not require authentication. Because the malicious payload is stored and executed in victims’ browsers, the risk of exploitation is high. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of a published CVSS score, the attack vector and impact suggest a severity in the high‑to‑critical range.

Generated by OpenCVE AI on September 30, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Verge3D Publishing and E-Commerce plugin version 4.13.1 or later.
  • If an upgrade cannot be performed immediately, temporarily disable the file storage feature or restrict uploads to a whitelist of safe MIME types.
  • Scan the current file store for any files that may contain malicious code and delete them, and configure the server to enforce content type validation before serving files.

Generated by OpenCVE AI on September 30, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CWE-80

Wed, 30 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
Title Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-30T06:00:25.268Z

Reserved: 2026-09-17T14:09:46.747Z

Link: CVE-2026-92994

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T06:17:09.983

Modified: 2026-09-30T06:17:09.983

Link: CVE-2026-92994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)