CVE-2026-66707: WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Facebook for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 3.7.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66707?
The severity of CVE-2026-66707 is classified as high with a score of 7.1.
What type of vulnerability is CVE-2026-66707?
CVE-2026-66707 is a Cross Site Scripting (XSS) vulnerability affecting the Facebook for WooCommerce plugin.
How do I fix CVE-2026-66707?
To fix CVE-2026-66707, update the Facebook for WooCommerce plugin to version 3.7.6 or later.
Which software is affected by CVE-2026-66707?
CVE-2026-66707 affects the WordPress Facebook for WooCommerce plugin versions 3.7.5 and below.
What are the potential impacts of CVE-2026-66707?
The potential impacts of CVE-2026-66707 include unauthorized script execution in the user's browser, leading to data theft or defacement.