CVE-2026-14331: CWE-79 Cross-Site Scripting (XSS) in Subscribe2
Subscribe2 WordPress plugin versions before 10.46 contain a reflected Cross-Site Scripting (XSS) vulnerability. This occurs because the plugin does not properly escape user-supplied input before reflecting it in a public subscription form. An unauthenticated visitor who interacts with a crafted link can trigger script execution in their browser. The vulnerability has a CVSS score of 6.1, indicating medium severity.
AI Analysis
Technical Summary
CVE-2026-14331 is a reflected Cross-Site Scripting (CWE-79) vulnerability in the Subscribe2 WordPress plugin prior to version 10.46. The flaw arises from improper escaping of user-supplied values that are reflected into a public subscription form. This allows an attacker to craft a malicious link that, when visited by an unauthenticated user, executes arbitrary script code in the victim's browser. This vulnerability affects the confidentiality and integrity of user interactions with the subscription form but does not impact availability.
Potential Impact
Successful exploitation results in the execution of arbitrary scripts in the browser of an unauthenticated visitor interacting with the subscription form via a crafted link. This can lead to information disclosure and manipulation of client-side data within the context of the vulnerable site. There is no indication of impact on system availability or authenticated users from the provided data.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should exercise caution with untrusted input and consider temporary mitigations such as disabling the vulnerable form or applying web application firewall rules to block suspicious input patterns.
CVE-2026-14331: CWE-79 Cross-Site Scripting (XSS) in Subscribe2
Description
Subscribe2 WordPress plugin versions before 10.46 contain a reflected Cross-Site Scripting (XSS) vulnerability. This occurs because the plugin does not properly escape user-supplied input before reflecting it in a public subscription form. An unauthenticated visitor who interacts with a crafted link can trigger script execution in their browser. The vulnerability has a CVSS score of 6.1, indicating medium severity.
CVSS v3.1
Score 6.1medium
Affected software
Subscribe2
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14331 is a reflected Cross-Site Scripting (CWE-79) vulnerability in the Subscribe2 WordPress plugin prior to version 10.46. The flaw arises from improper escaping of user-supplied values that are reflected into a public subscription form. This allows an attacker to craft a malicious link that, when visited by an unauthenticated user, executes arbitrary script code in the victim's browser. This vulnerability affects the confidentiality and integrity of user interactions with the subscription form but does not impact availability.
Potential Impact
Successful exploitation results in the execution of arbitrary scripts in the browser of an unauthenticated visitor interacting with the subscription form via a crafted link. This can lead to information disclosure and manipulation of client-side data within the context of the vulnerable site. There is no indication of impact on system availability or authenticated users from the provided data.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should exercise caution with untrusted input and consider temporary mitigations such as disabling the vulnerable form or applying web application firewall rules to block suspicious input patterns.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-01T12:37:32.093Z
- State
- PUBLISHED
Threat ID: 6a75772fbf8831d539df5e49
Added to database: 08/07/2026, 06:11:59 UTC
Last enriched: 08/14/2026, 15:58:36 UTC
Last updated: 09/21/2026, 22:01:32 UTC
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.