CVE-2026-66611: WordPress Paymob for WooCommerce plugin <= 4.1.10 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Paymob for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 4.1.11
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so the attacker does not need an account or existing WordPress privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
Which installations should be prioritized for remediation?
Sites running Paymob for WooCommerce version 4.1.10 or earlier are identified as affected. The supplied information does not state whether any particular plugin configuration prevents exposure.
What impact can successful exploitation have?
The supplied severity vector indicates low confidentiality, integrity, and availability impact, with scope changed. The issue is classified as cross-site scripting, so user interaction is part of the exploitation conditions.