Hi @wpmakenorg,
Thanks for flagging it, and sorry you saw it from a scanner before you saw it from me. That is CVE-2026-65545. It is fixed in 3.6.9, which is out now.
The short version of what it was: a visitor could leave a chatbot message containing HTML, and when an administrator later opened that conversation in the Discussions screen, the message was rendered as live HTML instead of text. The screen had protection against this, but it only matched lowercase tag names, so a differently cased tag slipped through. Discussions no longer turns any part of a stored message into HTML, whatever it is written as.
You are affected only if you use the Chatbot with Discussions enabled, and only an administrator opening the conversation could trigger it. Updating is enough, there is nothing to clean up.
I have sent the patch to Patchstack for validation, so their entry will stop reporting it shortly.
By the way, every security report I receive gets a fix released within 24 hours. This one was reported to Patchstack in May and their notification never reached me, which is my failure to catch and something I have now changed on my side so it cannot happen again! ☺️
Have a nice week-end,
Jordy.