CVE-2026-66456: WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
Published Aug 13, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
Affected Software
1 affected component
WordPress Profile Extra Fields by BestWebSoft<=1.3.4
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66456?
The severity of CVE-2026-66456 is rated medium with a CVSS score of 6.5.
2
What kind of vulnerability is CVE-2026-66456?
CVE-2026-66456 is a Cross Site Scripting (XSS) vulnerability affecting the Profile Extra Fields by BestWebSoft plugin.
3
How do I fix CVE-2026-66456?
To fix CVE-2026-66456, update the Profile Extra Fields by BestWebSoft plugin to version 1.3.5 or later.
4
Who is affected by CVE-2026-66456?
CVE-2026-66456 affects WordPress sites using the Profile Extra Fields by BestWebSoft plugin version 1.3.4 or earlier.
5
What can attackers do with CVE-2026-66456?
Attackers can exploit CVE-2026-66456 to carry out Cross Site Scripting (XSS) attacks on subscribers.