WordPress Plugin Vulnerabilities

Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting

Description

The plugin does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators.

Proof of Concept

Affects Plugins

Fixed in 1.6.3

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)

Other