CVE-2026-66706: WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
Published Aug 6, 2026
·Updated
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Affected Software
1 affected component
WordPress Subscribe to Comments plugin<=2.3.1
Event History
Aug 6, 2026
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66706?
The severity of CVE-2026-66706 is rated as medium with a score of 5.9.
2
How do I fix CVE-2026-66706?
To fix CVE-2026-66706, update the WordPress Subscribe to Comments plugin to version 2.3.2 or later.
3
What type of vulnerability is CVE-2026-66706?
CVE-2026-66706 is a Cross Site Scripting (XSS) vulnerability.
4
What software is affected by CVE-2026-66706?
CVE-2026-66706 affects the WordPress Subscribe to Comments plugin versions up to 2.3.1.
5
What impact does CVE-2026-66706 have on the system?
The impact of CVE-2026-66706 allows an attacker to conduct XSS attacks, potentially compromising user interactions.