CVE-2026-66711
Received Received - Intake

Subscriber XSS in WooCommerce Multilingual & Multicurrency

Vulnerability report for CVE-2026-66711, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Patchstack

Description

Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpml woocommerce_multilingual_and_multicurrency to 5.5.6 (inc)
wpengine woocommerce_multilingual to 5.5.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Subscriber Cross Site Scripting (XSS) issue found in WooCommerce Multilingual & Multicurrency plugin versions up to 5.5.6. XSS allows attackers to inject malicious scripts into web pages viewed by other users. In this case, subscribers with low privileges could exploit it to run scripts in the context of other users.

Detection Guidance

Detecting this XSS vulnerability requires checking the installed version of the WooCommerce Multilingual & Multicurrency plugin. Verify if the version is 5.5.6 or below. If so, the system is vulnerable. No specific commands are provided in the context, but manual inspection of the plugin version in WordPress admin or via file system checks (e.g., wp-content/plugins/woocommerce-multilingual-and-multicurrency/woocommerce-multilingual.php) can confirm exposure.

Impact Analysis

If exploited, this vulnerability could allow attackers to steal sensitive user data, hijack user sessions, or perform actions on behalf of other users. For website owners, it may lead to compromised user accounts, data breaches, or reputational damage. Users could face phishing attacks or unauthorized access to their accounts.

Compliance Impact

This vulnerability could lead to violations of GDPR and HIPAA by exposing personal or health data. GDPR requires protecting user data, and a breach could result in fines. HIPAA mandates safeguarding health information, and an XSS flaw could lead to unauthorized access, triggering compliance violations and penalties.

Mitigation Strategies

Update WooCommerce Multilingual & Multicurrency to the latest version, which should be greater than 5.5.6. If an update is not available, consider disabling the plugin temporarily until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66711. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart