CVE-2026-66643: WordPress Wufoo Shortcode plugin <= 1.55 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
Affected Software
1 affected component
WordPress Wufoo Shortcode plugin<=1.55
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The affected versions are Wufoo Shortcode versions 1.55 and earlier. The issue is identified as contributor-level XSS, so exploitation requires contributor privileges.
2
What are the practical exploitation conditions and potential impact?
The CVSS vector indicates the attack can be performed over the network with low complexity, but requires user interaction. It also indicates that confidentiality, integrity, and availability may each be affected at a low level, with impacts extending beyond the vulnerable security authority.