CVE-2026-66597

WordPress wpDataTables plugin <= 6.5.1.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.


We have discovered 1,692 live websites that are affected by CVE-2026-66597.

Run a Free Instant Scan




Affected Software

Product  Wpdatatables
Category Wordpress Plugins
Vulnerable Domains1,692 live websites (52% of Wpdatatables install base)
Vulnerable Versions
  • from 0 through 6.5.1.4
Vulnerable Versions Count165 versions ( 86% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 20, 2026
  • Updated - Aug 20, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66597
United States489 websites



Germany135 websites
Russia76 websites
GB72 websites
France63 websites
Netherlands59 websites
India59 websites
Italy57 websites
Canada46 websites
Poland40 websites

Website Distribution by TLD

Number of websites using CVE-2026-66597
.com628 websites
.org126 websites
.de78 websites
.ru64 websites
.nl51 websites
.net42 websites
.co.uk41 websites
.it40 websites
.cz33 websites
.pl32 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66597

Top websites that are affected by CVE-2026-66597. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org Germany*,***
***.**.gov United States**,***
********.***.uk United States**,***
*************.com Canada***,***
***.edu United States***,***
**************.com United States***,***
***.******.edu United States***,***
****************.com United States***,***
*************.***.uk GB***,***
********.***.ws Samoa***,***
See full domain list

FAQ

CVE-2026-66597 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wpdatatables
A total of 1,692 websites have been identified as vulnerable to CVE-2026-66597, based on global website indexing conducted by WebTechSurvey.
The Wpdatatables is affected by the CVE-2026-66597 vulnerability.
Wpdatatables versions up to and including 6.5.1.4 are vulnerable to CVE-2026-66597.