CVE-2026-66711: WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce Multilingual & Multicurrency pluginto a version that resolves this vulnerability.Fixed in 5.5.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66711?
The severity of CVE-2026-66711 is high with a score of 7.1.
What type of vulnerability is CVE-2026-66711?
CVE-2026-66711 is a Cross Site Scripting (XSS) vulnerability affecting the WooCommerce Multilingual & Multicurrency plugin.
Which versions of the plugin are affected by CVE-2026-66711?
CVE-2026-66711 affects WooCommerce Multilingual & Multicurrency plugin versions up to and including 5.5.6.
How can I fix CVE-2026-66711?
To fix CVE-2026-66711, update the WooCommerce Multilingual & Multicurrency plugin to the latest version.
Who is vulnerable to CVE-2026-66711?
Subscribers using the affected versions of the WooCommerce Multilingual & Multicurrency plugin are vulnerable to CVE-2026-66711.