CVE-2026-66655
Deferred Deferred - Pending Action

Unauthenticated XSS in MultiParcels Shipping For WooCommerce

Vulnerability report for CVE-2026-66655, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Patchstack

Description

Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-09-03
AI Q&A
2026-08-13
EPSS Evaluated
2026-09-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack multi_parcels_shipping_for_woocommerce to 1.30.36 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Unauthenticated Cross Site Scripting (XSS) vulnerability in the MultiParcels Shipping For WooCommerce plugin versions 1.30.36 and below. It allows attackers to inject malicious scripts into websites without authentication. The flaw requires user interaction, such as clicking a malicious link, to execute harmful actions like redirects or advertisements.

Detection Guidance

Since this is a reflected XSS vulnerability in a WordPress plugin, detection involves checking for suspicious inputs or script injections in web requests. Monitor server logs for unusual JavaScript payloads in URLs or form submissions. Use tools like Wordfence or Sucuri to scan for malicious activity. No specific commands are provided in the context.

Impact Analysis

Attackers could exploit this to inject malicious scripts, potentially leading to website redirects, unwanted advertisements, or other harmful actions when visitors access the site. Since it requires user interaction, visitors must click a malicious link or visit a crafted page for the attack to succeed.

Compliance Impact

This XSS vulnerability could expose websites to risks that may violate compliance standards like GDPR or HIPAA. For example, attackers could steal user session cookies or sensitive data entered on forms, leading to unauthorized access or data breaches. Such incidents could result in regulatory penalties under GDPR for data protection failures or HIPAA for compromised health information.

Mitigation Strategies

Immediately apply the Patchstack mitigation rule to block attacks until an official patch is released. Consider temporarily disabling the MultiParcels Shipping For WooCommerce plugin if no alternative exists. Update the plugin as soon as an official fix is available. Seek assistance from a hosting provider or developer if needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66655. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart