Junglewise Threat Intelligence

CVE-2026-66707: Meta Facebook for WooCommerce unauthenticated XSS

CVE-2026-66707 · Severity: high · CVSS 7.1 · Published 2026-08-06

Vendors: Meta.

Executive brief

Facebook for WooCommerce is a WordPress plugin that integrates Facebook's commerce features with WooCommerce online stores. Versions 3.7.5 and earlier contain an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the website. Successful exploitation requires user interaction and could enable attackers to steal visitor data, hijack customer accounts, or compromise store operations.

Technical details

This is a stored or reflected cross-site scripting (XSS) vulnerability in the Facebook for WooCommerce WordPress plugin (versions ≤3.7.5). The vulnerability allows unauthenticated attackers to inject malicious JavaScript code that executes in the context of website visitors' browsers. While the attack is unauthenticated at the network level, successful exploitation requires user interaction—typically a victim clicking a malicious link or visiting a crafted page. An attacker can steal session cookies, payment information, customer data, or perform actions on behalf of authenticated users. The vulnerability was patched in version 3.7.6.

Affected products

  • Meta Facebook for WooCommerce <=3.7.5

Timeline

  • 2026-07-03: disclosed
  • 2026-07-31: patched: Version 3.7.6 released with patch
  • 2026-08-06: advisory

References

Related threats