WordPress Plugin Vulnerabilities

Subscribe2 < 10.46 - Reflected XSS via email Parameter

Description

The plugin does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.

Proof of Concept

Affects Plugins

Fixed in 10.46

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Omar Elshopky
Submitter
Omar Elshopky
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 27 days ago)
Added
2026-08-03 (about 26 days ago)
Last Updated
2026-08-03 (about 26 days ago)

Other