Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 30 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 CWE-80 |
Wed, 30 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it. | |
| Title | Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-30T13:37:21.649Z
Reserved: 2026-09-17T14:09:46.747Z
Link: CVE-2026-92994
Updated: 2026-09-30T13:21:20.443Z
Status : Received
Published: 2026-09-30T06:17:09.983
Modified: 2026-09-30T14:17:34.553
Link: CVE-2026-92994
No data.
OpenCVE Enrichment
Updated: 2026-09-30T12:30:17Z