CVE-2026-73182: WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability
Published Aug 19, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
Affected Software
1 affected component
WordPress BBQ Pro plugin<=3.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BBQ Pro pluginto a version that resolves this vulnerability.Fixed in 3.9.1
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation still requires user interaction, as reflected by the UI:R vector.
2
Which plugin versions are affected?
BBQ Pro versions 3.9 and earlier are affected according to the available data.