CVE-2026-96836: WordPress Parsi Date plugin <= 6.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Parsi Date pluginto a version that resolves this vulnerability.Fixed in 6.4
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
Which installations are affected?
WordPress sites using the Parsi Date plugin version 6.3 or earlier are affected according to the available information. The data does not state whether a particular plugin configuration is required.
What impact could successful exploitation have?
The CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. As an XSS issue, successful exploitation could run attacker-supplied script in a user’s browser context after the required interaction.
How can I determine whether my site is affected?
Check whether the WordPress Parsi Date plugin is installed and identify its installed version. Versions 6.3 and earlier fall within the reported affected range.