CVE-2026-66644: WordPress Typing Effect plugin <= 1.3.7 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
Affected Software
1 affected component
WordPress Typing Effect plugin<=1.3.7
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
How can I determine whether my site is potentially affected?
WordPress sites running Typing Effect version 1.3.7 or earlier are potentially affected. Sites without the plugin or with a version outside the stated affected range are not identified as affected by the provided data.
2
What access does an attacker need to exploit this issue?
Exploitation requires low-level authenticated access, specifically contributor-level access according to the vulnerability information. The CVSS vector also indicates user interaction is required.