What is CVE-2026-66639?
A Stored Cross-Site Scripting (XSS) vulnerability was identified in WPZOOM Forms – Contact Form Plugin for Gutenberg versions <= 2.0.4, exploitable by Contributor-level users. This flaw allows the injection of malicious scripts, compromising site security. Updating to the latest version of the plugin is recommended.
Azərbaycanca: WPZOOM Forms – Contact Form Plugin for Gutenberg plagininin 2.0.4 və daha aşağı versiyalarında "Contributor" səviyyəli istifadəçilər tərəfindən icra edilə bilən Saxlanılmış Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Bu boşluq, zərərli skriptlərin daxil edilməsinə imkan verərək saytın təhlükəsizliyini riskə atır. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which level of users can exploit the CVE-2026-66639 vulnerability in the WPZOOM Forms plugin?
Contributor-level users can exploit this vulnerability.
Which versions of the WPZOOM Forms plugin are affected by CVE-2026-66639?
This vulnerability affects WPZOOM Forms plugin versions 2.0.4 and below.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.