AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66687

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

WpBookingly versions up to 1.3.2 are vulnerable to a Customer Cross Site Scripting (XSS) attack, which could allow an attacker to inject malicious scripts into web pages viewed by users. This vulnerability poses a risk of data theft and session hijacking, making it critical for organizations using this plugin to prioritize updates. Users and administrators of affected systems should take immediate action to mitigate potential exploitation.

CVE
CVE-2026-66687
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%

Original NVD Description

Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.