CVE-2026-66460 MEDIUM

CVE-2026-66460: WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability

Vendor Aftership & Automizely
Product AfterShip Tracking
Weakness CWE-79 · XSS
Published August 13, 2026
Last update August 13, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

AfterShip Tracking versions up to 1.18.1 contain a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious scripts. A logged-in user must visit a crafted page or link for the attack to execute. The vulnerability can affect other users and compromise site integrity, though the impact is limited to low-severity data exposure.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that execute in other users' browsers when they visit a crafted page.

Potential impact on your site

04Site Impact

Logged-in users could have their sessions compromised or data stolen if they visit attacker-controlled pages.

Conditions required to exploit

05Prerequisites

Attacker needs a low-privilege account and the victim must click a malicious link or visit a crafted page.

Key dates

06Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated

Related vulnerabilities

08Related CVE