What is CVE-2026-66643?
A Cross Site Scripting (XSS) vulnerability has been identified in Wufoo Shortcode plugin versions 1.55 and below, exploitable by Contributor-level users. This could allow an attacker to execute malicious scripts in a victim's browser. Immediate update to the latest version is recommended.
Azərbaycanca: Wufoo Shortcode plagininin 1.55 və aşağı versiyalarında "Contributor" səviyyəli istifadəçilər tərəfindən həyata keçirilə bilən Cross Site Scripting (XSS) zəifliyi aşkarlanıb. Bu zəiflik təcavüzkara qurbanın brauzerində zərərli skript icra etməyə imkan verə bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which user level can exploit the CVE-2026-66643 vulnerability in the Wufoo Shortcode plugin?
This XSS vulnerability can be exploited specifically by Contributor-level users.
Which versions of the Wufoo Shortcode plugin are affected by CVE-2026-66643?
Plugin versions 1.55 and below are affected by this XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.