CVE-2026-66610

WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.


We have discovered 305 live websites that are affected by CVE-2026-66610.

Run a Free Instant Scan




Affected Software

Product  Urna
Category Wordpress Themes
Vulnerable Domains305 live websites (100% of Urna install base)
Vulnerable Versions
  • from 0 through 2.6.2
Vulnerable Versions Count2 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • Khuong Hai & Thanh Nam (HPT Vietnam) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66610
United States76 websites



India24 websites
Germany20 websites
Cyprus14 websites
Romania13 websites
Turkey12 websites
GB10 websites
France8 websites
Russia7 websites
Singapore7 websites

Website Distribution by TLD

Number of websites using CVE-2026-66610
.com138 websites
.de6 websites
.it6 websites
.co.uk5 websites
.com.br5 websites
.pl4 websites
.ru4 websites
.eu4 websites
.net3 websites
.nl3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66610

Top websites that are affected by CVE-2026-66610. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States***,***
***************.***.vn Vietnam***,***
********.com Turkey*,***,***
**********.**.ua Ukraine*,***,***
****************.ru Russia*,***,***
********.com Turkey*,***,***
********.lt Lithuania*,***,***
*******.se Sweden*,***,***
*******.gr Greece*,***,***
*****.pl Poland*,***,***
See full domain list

FAQ

CVE-2026-66610 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Urna
A total of 305 websites have been identified as vulnerable to CVE-2026-66610, based on global website indexing conducted by WebTechSurvey.
The Urna is affected by the CVE-2026-66610 vulnerability.
Urna versions up to and including 2.6.2 are vulnerable to CVE-2026-66610.