CVE-2026-66621: WordPress Ultimate Dashboard plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ultimate Dashboard pluginto a version that resolves this vulnerability.Fixed in 3.11.2
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin-specific privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
Which installations are affected, and is a fixed version identified?
Installations running Ultimate Dashboard version 3.11.2 or earlier are affected according to the available information. The data does not identify a fixed version or provide a workaround for deployments that cannot patch immediately.
Can I determine whether this vulnerability has already been exploited?
The supplied information does not describe the vulnerable input, endpoint, or any log indicators. As a result, it cannot be used to determine from logs whether exploitation has already occurred.