PatchSiren

Subscribe2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Subscribe2 CVE published 2026-08-07

CVE-2026-14331

The Subscribe2 WordPress plugin before version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can craft a malicious link that, when interacted with, executes arbitrary JavaScript in the browser of an unauthenticated visitor. This is due to the plugin's failure to properly escape user-supplied values before reflecting them into a public subscription form. The vulnerability has a C [truncated]