CVE-2026-66610: WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Affected Software
1 affected component
WordPress Urna Theme<=2.6.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Urna Themeto a version that resolves this vulnerability.Fixed in 2.6.3
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What impact could successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. This is an XSS issue, so impact occurs in the context reached through the vulnerable theme.