PT-2026-97195 · WordPress · Subscribe Forms
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Subscribe Forms versions prior to 1.6.3
Description
Stored Cross-Site Scripting (XSS) occurs because the plugin fails to sanitize and escape a form setting before it is output on a page. This allows authenticated users with the Author role or higher to inject malicious scripts that execute in the browser of any visitor viewing the page containing the form, including administrators and unauthenticated users.
Recommendations
Update Subscribe Forms to version 1.6.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Subscribe Forms