Junglewise Threat Intelligence

CVE-2026-66607: Advance Product Search cross-site scripting

CVE-2026-66607 · Severity: high · CVSS 7.1 · Published 2026-08-20

Vendors: Wordpress.

Executive brief

Advance Product Search is a WordPress plugin used to enhance product search functionality on e-commerce sites. The plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by site visitors. An exploit could enable attackers to steal visitor session data, hijack customer accounts, or perform unauthorized actions on behalf of compromised users.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in Advance Product Search plugin versions 1.4.8 and earlier that requires user interaction (such as clicking a malicious link) to exploit. The attack is unauthenticated, meaning no special privileges are required to craft the exploit, though a privileged user (such as a site administrator or customer) must be tricked into clicking a malicious link or visiting a crafted page. An attacker can inject arbitrary JavaScript code that executes in the context of the vulnerable WordPress site, potentially allowing theft of sensitive data, session hijacking, or account takeover. The vulnerability has been patched in version 1.4.9; users should update immediately.

Affected products

  • WordPress Advance Product Search 1.4.8 and earlier

Timeline

  • 2026-08-19: disclosed: Vulnerability reported to Patchstack
  • 2026-08-20: advisory: CVE-2026-66607 published
  • 2026-08-19: patched: Fix released in version 1.4.9

References