AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66440

HIGH · CVSS 7.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated cross-site scripting (XSS) in WPIDE – File Manager & Code Editor versions up to 3.5.7, enabling attackers to execute arbitrary scripts in the context of users accessing the application. This can lead to data theft, session hijacking, or defacement of the web application. Organizations using affected versions should prioritize remediation to protect against potential exploits targeting their users.

CVE
CVE-2026-66440
Severity
HIGH
CVSS
7.1
EPSS
0.19%

Original NVD Description

Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.