WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in YMC Filter

A powerful and flexible plugin to filter and display posts, custom post types, and other content in beautifully designed grid layouts.

9Reported vulnerabilities
9.8Highest CVSS score
3.12.14Latest version
4,000+Active installs

What to do now

Update YMC Filter to 3.12.9 or later. 9 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 16, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-6164 Critical 9.8 1.1% Before 2.8.33 2.8.33 July 18, 2024
CVE-2026-54836 High 7.5 1.3% 3.11.5 and earlier 3.11.6 June 18, 2026
CVE-2024-39665 Medium 6.4 0.3% 2.9.2 and earlier 2.9.3 August 1, 2024
CVE-2026-16559 Medium 6.4 0.2% 3.12.8 and earlier 3.12.9 August 3, 2026
CVE-2026-16558 Medium 6.4 0.1% 3.12.7 and earlier 3.12.8 August 3, 2026
CVE-2026-10823 Medium 5.3 1.5% 3.11.2 and earlier 3.11.3 June 5, 2026
CVE-2025-10289 Medium 5.9 0.3% 3.2.0 and earlier 3.2.1 December 12, 2025
CVE-2026-32397 Medium 5.3 0.2% 3.5.1 and earlier 3.5.2 February 20, 2026
CVE-2024-39664 Medium 4.3 0.4% 2.8.33 and earlier 2.8.34 August 1, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.