CVE-2026-66607: WordPress Advance Product Search plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
Affected Software
1 affected component
WordPress Advance Product Search<=1.4.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Advance Product Search pluginto a version that resolves this vulnerability.Fixed in 1.4.9 - Operational
Update the WordPress "Advance Product Search" plugin from versions <= 1.4.8 to at least 1.4.9 to address the unauthenticated XSS vulnerability (Cross Site Scripting).
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access to the affected site. Exploitation does require user interaction, as indicated by the UI:R vector.
2
What versions are affected?
Advance Product Search versions up to and including 1.4.8 are affected.