AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66706

MEDIUM · CVSS 5.9 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Subscribe to Comments plugin versions up to 2.3.1 are vulnerable to a Cross Site Scripting (XSS) attack, allowing attackers to inject malicious scripts into web pages viewed by users. This vulnerability can lead to unauthorized actions or data exposure, particularly affecting users who interact with the comments section. Website administrators using this plugin should prioritize patching or updating to mitigate potential exploitation.

CVE
CVE-2026-66706
Severity
MEDIUM
CVSS
5.9
EPSS
0.15%

Original NVD Description

Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.