PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14331 Subscribe2 CVE debrief

The Subscribe2 WordPress plugin before version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can craft a malicious link that, when interacted with, executes arbitrary JavaScript in the browser of an unauthenticated visitor. This is due to the plugin's failure to properly escape user-supplied values before reflecting them into a public subscription form. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. Users of the Subscribe2 WordPress plugin, WordPress administrators, security teams monitoring for web application vulnerabilities, and operators of platforms that utilize the Subscribe2 plugin should be aware of this vulnerability. They should review their installations, monitor for suspicious activity, and apply updates or mitigations as necessary to prevent exploitation. Defenders should verify the version of the Subscribe2 plugin in use, check for any suspicious interactions with subscription forms, and ensure that proper input validation and output encoding are in place. Additionally, defenders should be aware of the potential for attackers to craft malicious links to exploit this vulnerability. The evidence for this CVE comes primarily from official CVE and NVD sources.

Vendor
Subscribe2
Product
Subscribe2 WordPress plugin
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-26
Advisory published
2026-08-07
Advisory updated
2026-08-26

Who should care

Users of the Subscribe2 WordPress plugin, WordPress administrators, security teams monitoring for web application vulnerabilities, and operators of platforms that utilize the Subscribe2 plugin should be aware of this vulnerability. They should review their installations, monitor for suspicious activity, and apply updates or mitigations as necessary to prevent exploitation.

Technical summary

The Subscribe2 WordPress plugin before version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can craft a malicious link that, when interacted with, executes arbitrary JavaScript in the browser of an unauthenticated visitor. This is due to the plugin's failure to properly escape user-supplied values before reflecting them into a public subscription form. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity.

Defensive priority

Medium-priority defensive review recommended due to publicly available exploit vector.

Recommended defensive actions

  • Review and apply Subscribe2 plugin updates
  • Inventory WordPress installations for Subscribe2 plugin usage
  • Monitor for suspicious interactions with subscription forms
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The evidence for this CVE comes primarily from official CVE and NVD sources. The Subscribe2 WordPress plugin before version 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form. This leads to Reflected Cross-Site Scripting (XSS) that can execute in the browser of an unauthenticated visitor who interacts with the form through a crafted link. Defenders should verify the version of the Subscribe2 plugin in use, check for any suspicious interactions with subscription forms, and ensure that proper input validation and output encoding are in place. Additionally, defenders should be aware of the potential for attackers to craft malicious links to exploit this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14331 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14331

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14331 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14331

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.