CVE-2026-66467: WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability
Published Aug 13, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
Affected Software
1 affected component
wordpress/FluentCommunity<=2.7.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/FluentCommunityto a version that resolves this vulnerability.Fixed in 2.7.7
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66467?
The severity of CVE-2026-66467 is medium with a score of 6.5.
2
What type of vulnerability is CVE-2026-66467?
CVE-2026-66467 is a Cross Site Scripting (XSS) vulnerability affecting versions of the FluentCommunity plugin before 2.7.5.
3
How do I fix CVE-2026-66467?
To fix CVE-2026-66467, update the FluentCommunity plugin to version 2.7.6 or later.
4
Who is affected by CVE-2026-66467?
CVE-2026-66467 affects users with subscriber roles on WordPress sites using the FluentCommunity plugin version 2.7.5 or earlier.
5
When was CVE-2026-66467 published?
CVE-2026-66467 was published on August 13, 2026.