CVE-2026-66697: WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerceto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66697?
The severity of CVE-2026-66697 is rated high at 7.1.
What type of vulnerability is CVE-2026-66697?
CVE-2026-66697 is a Cross Site Scripting (XSS) vulnerability.
How can I fix CVE-2026-66697?
To fix CVE-2026-66697, update the Colissimo Officiel plugin for WooCommerce to version 2.10.1 or higher.
Which software is affected by CVE-2026-66697?
The affected software is the Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin version 2.10.0 and lower.
What are the implications of CVE-2026-66697?
CVE-2026-66697 allows unauthenticated users to execute scripts in the context of another user, potentially leading to data theft or session hijacking.