Cross Site Scripting Vulnerability in Advance Product Search Plugin
CVE-2026-66607
7.1HIGH
What is CVE-2026-66607?
An unauthenticated Cross Site Scripting (XSS) vulnerability exists in the Advance Product Search plugin for WordPress, specifically affecting versions up to 1.4.8. This flaw allows attackers to inject malicious scripts into webpages viewed by users, compromising site security and potentially leading to unauthorized actions or data theft. It is imperative for users of the affected plugin to apply security updates and practice good web hygiene to mitigate risks.
Affected Version(s)
Advance Product Search <= 1.4.8