CVE-2026-66617: WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PublishPress Series pluginto a version that resolves this vulnerability.Fixed in 3.1.4
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs Contributor-level access to a WordPress site using an affected PublishPress Series version. Exploitation also requires a user to interact with attacker-supplied content.
Is this exploitable without logging in?
No. The supplied CVSS vector indicates low privileges are required, and the description specifically identifies Contributor XSS.
What impact can successful exploitation have?
Successful XSS can affect confidentiality, integrity, and availability at low impact levels. The CVSS vector also indicates the vulnerability can affect a security scope beyond the vulnerable component.