CVE-2026-92994: Unknown VERGE3D Publishing And E-Commerce
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.
Affected products
- Unknown VERGE3D Publishing And E-Commerce: before 4.13.1 (fixed in 4.13.1)
Published 2026-09-30. Last modified 2026-09-30.