CVE-2026-14331
Received Received - Intake

Subscribe2 WordPress Plugin Reflected XSS Vulnerability

Vulnerability report for CVE-2026-14331, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: WPScan

Description

The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
subscribe2 plugin to 10.46 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Reflected Cross-Site Scripting (XSS) vulnerability in the Subscribe2 WordPress plugin versions before 10.46. It occurs because the plugin does not properly escape user-supplied input in the email parameter of a public subscription form. Attackers can exploit this by crafting a malicious link that injects and executes scripts in the browsers of unauthenticated visitors who interact with the form.

Detection Guidance

Check the installed version of the Subscribe2 plugin in WordPress. If it is below 10.46, the system is vulnerable. Use WordPress admin panel or run SQL query on the database to check the plugin version.

Impact Analysis

An attacker could trick users into clicking a malicious link, leading to the execution of arbitrary scripts in their browsers. This could result in theft of session cookies, account takeovers, or redirection to phishing sites. Unauthenticated visitors are at risk if they interact with the affected subscription form.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations using the vulnerable plugin may face compliance breaches if user data is compromised through this XSS flaw.

Mitigation Strategies

Update the Subscribe2 plugin to version 10.46 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14331. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart