What is CVE-2026-66636?
A stored Cross Site Scripting (XSS) vulnerability has been found in Wise Chat plugin version 3.4 and below, exploitable by users with the 'Contributor' role. This may allow execution of malicious scripts; updating to the latest version is strongly recommended.
Azərbaycanca: Wise Chat plagini 3.4 və daha aşağı versiyalarında 'Contributor' rolu ilə daxil olmuş istifadəçilər tərəfindən saxlanılan Cross Site Scripting (XSS) zəifliyi aşkar edilib. Bu, zərərli skriptlərin icrasına imkan yaradır; plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Wise Chat plugin are affected by the stored XSS vulnerability CVE-2026-66636?
Wise Chat plugin versions 3.4 and below are affected by this stored XSS vulnerability.
What role must an attacker log in with to exploit the CVE-2026-66636 vulnerability?
The attacker must log in with the 'Contributor' role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.