CVE-2026-66639: WordPress WPZOOM Forms – Contact Form plugin for Gutenberg plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
Affected Software
1 affected component
WordPress WPZOOM Forms – Contact Form plugin for Gutenberg<=2.0.4
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions are affected and how severe is the issue?
The affected versions are 2.0.4 and earlier. The issue is classified as medium severity with a CVSS score of 6.5.
2
What access and conditions does an attacker need to exploit this vulnerability?
An attacker needs Contributor-level privileges and user interaction to exploit the XSS issue. The vector is network-accessible, and successful exploitation can affect confidentiality, integrity, and availability to a limited extent.