What is CVE-2026-66596?
The WordPress Newsletter plugin (versions <= 9.3.3) contains an unauthenticated Cross Site Scripting (XSS) vulnerability. This allows a remote attacker to execute arbitrary code in the user's browser. It is recommended to update the plugin to the latest version immediately.
Azərbaycanca: WordPress Newsletter plaqini (9.3.3 və aşağı versiyalar) autentifikasiya olunmamış Cross Site Scripting (XSS) zəifliyinə malikdir. Bu, uzaqdan hücum edənə istifadəçi brauzerində özbaşına kod icra etməyə imkan verir. Plaqini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What software product is affected by the CVE-2026-66596 vulnerability?
This vulnerability affects the WordPress Newsletter plugin in versions 9.3.3 and below.
What can a remote attacker achieve by exploiting CVE-2026-66596?
The attacker can execute arbitrary code in the user's browser, as this is an unauthenticated XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.