CVE-2026-66577: WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2026
·Updated
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
Affected Software
1 affected component
WordPress JetSearch plugin<=3.6.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JetSearch pluginto a version that resolves this vulnerability.Fixed in 3.6.3.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as contributor XSS, so an attacker needs Contributor-level access to a WordPress site using an affected JetSearch version.
2
Does exploitation require interaction from another user?
Yes. The CVSS vector includes UI:R, indicating that exploitation requires user interaction.
3
What security impact can exploitation have?
The supplied CVSS vector indicates low impacts to confidentiality, integrity, and availability, with the impact scope extending beyond the vulnerable component (S:C).