PatchSiren cyber security CVE debrief
CVE-2026-14331 Subscribe2 CVE debrief
The Subscribe2 WordPress plugin before version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can craft a malicious link that, when interacted with, executes arbitrary JavaScript in the browser of an unauthenticated visitor. This is due to the plugin's failure to properly escape user-supplied values before reflecting them into a public subscription form. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. Users of the Subscribe2 WordPress plugin, WordPress administrators, security teams monitoring for web application vulnerabilities, and operators of platforms that utilize the Subscribe2 plugin should be aware of this vulnerability. They should review their installations, monitor for suspicious activity, and apply updates or mitigations as necessary to prevent exploitation. Defenders should verify the version of the Subscribe2 plugin in use, check for any suspicious interactions with subscription forms, and ensure that proper input validation and output encoding are in place. Additionally, defenders should be aware of the potential for attackers to craft malicious links to exploit this vulnerability. The evidence for this CVE comes primarily from official CVE and NVD sources.
- Vendor
- Subscribe2
- Product
- Subscribe2 WordPress plugin
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-08-26
Who should care
Users of the Subscribe2 WordPress plugin, WordPress administrators, security teams monitoring for web application vulnerabilities, and operators of platforms that utilize the Subscribe2 plugin should be aware of this vulnerability. They should review their installations, monitor for suspicious activity, and apply updates or mitigations as necessary to prevent exploitation.
Technical summary
The Subscribe2 WordPress plugin before version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can craft a malicious link that, when interacted with, executes arbitrary JavaScript in the browser of an unauthenticated visitor. This is due to the plugin's failure to properly escape user-supplied values before reflecting them into a public subscription form. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity.
Defensive priority
Medium-priority defensive review recommended due to publicly available exploit vector.
Recommended defensive actions
- Review and apply Subscribe2 plugin updates
- Inventory WordPress installations for Subscribe2 plugin usage
- Monitor for suspicious interactions with subscription forms
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The evidence for this CVE comes primarily from official CVE and NVD sources. The Subscribe2 WordPress plugin before version 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form. This leads to Reflected Cross-Site Scripting (XSS) that can execute in the browser of an unauthenticated visitor who interacts with the form through a crafted link. Defenders should verify the version of the Subscribe2 plugin in use, check for any suspicious interactions with subscription forms, and ensure that proper input validation and output encoding are in place. Additionally, defenders should be aware of the potential for attackers to craft malicious links to exploit this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14331 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14331
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14331 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14331
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/5ea58741-0c4c-4482-94dd-34721b19fc26/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.