Impact
The Subscribe2 WordPress plugin version 10.45 and earlier reflects a user‑supplied email parameter in a public subscription form without proper escaping. This allows a crafted link to inject arbitrary JavaScript that executes in the browser of any unauthenticated visitor. The flaw is a reflected cross‑site scripting vulnerability (CWE‑79).
Affected Systems
Any WordPress site that has the Subscribe2 plugin installed at a version earlier than 10.46 is affected. The vulnerability exists in the plugin code that renders the subscription form to public visitors.
Risk and Exploitability
Because the flaw is triggered by a crafted link to the public subscription form, an attacker can exploit it remotely without needing authentication. The CVSS score is 6.1, indicating a moderate level of severity. The EPSS score is less than 1%, suggesting low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Its exploitation requires only a public URL and can affect all visitors to the page containing the form.
OpenCVE Enrichment