MEDIUM
Mark Jaquith
CVE published 2026-08-06
CVE-2026-66706
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:23.547Z and has not been modified since then. This vulnerability, CVE-2026-66706, is an Author Cross Site Scripting (XSS) issue affecting the Subscribe to Comments plugin, particularly versions 2.3.1 or earlier. The vulnerability has a Medium severity with a CVSS score of 5.9, requiring use [truncated]