What is CVE-2026-66646?
This is a stored Cross-Site Scripting (XSS) vulnerability in WP Tab Widget plugin versions 1.2.11 and below, exploitable by contributor-level users. Update to the latest patched version to mitigate the issue.
Azərbaycanca: Bu, WP Tab Widget pluginin 1.2.11 və daha əvvəl versiyalarında contributor səviyyəli istifadəçilər tərəfindən həyata keçirilə bilən saxlanılmış XSS (Stored Cross-Site Scripting) zəifliyidir. Pluginin ən son təhlükəsizlik yeniləməsinə keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WP Tab Widget plugin are affected by CVE-2026-66646?
This stored XSS vulnerability affects WP Tab Widget plugin versions 1.2.11 and below.
What user role is required to exploit CVE-2026-66646?
The vulnerability can be exploited by contributor-level users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.