CVE-2026-66646: WordPress WP Tab Widget plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
Affected Software
1 affected component
wp-tab-widget<=1.2.11
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The affected component is WP Tab Widget version 1.2.11 and earlier. The issue is described as contributor XSS, so exploitation requires contributor-level privileges.
2
What are the practical exploitation conditions and impact?
The CVSS vector indicates network-reachable exploitation with low attack complexity, but it requires user interaction. Successful exploitation can affect confidentiality, integrity, and availability beyond the initially affected security scope.