Cross Site Scripting Vulnerability in Local Delivery Drivers for WooCommerce
CVE-2026-66468
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 August 2026
What is CVE-2026-66468?
A Cross Site Scripting (XSS) vulnerability exists in the Local Delivery Drivers for WooCommerce plugin, affecting versions up to 3.0.0. This security flaw allows unauthenticated users to inject malicious scripts into web pages viewed by other users. As a result, attackers could exploit this vulnerability to perform a range of malicious actions, potentially compromising user data or hijacking user sessions. It is crucial for users of this plugin to apply patches or updates to safeguard their WordPress sites from such vulnerabilities.
Affected Version(s)
Local Delivery Drivers for WooCommerce <= 3.0.0