Impact
An XSS vulnerability exists in the WordPress Subscribe to Comments plugin up to and including version 2.3.1. Based on the description, it is inferred that the flaw allows an attacker to inject arbitrary JavaScript into content that the plugin outputs, potentially leading to session hijacking, data theft, or defacement of pages. The weakness is described as a classic client-side injection problem, corresponding to CWE-79.
Affected Systems
The vulnerability affects WordPress sites that run Mark Jaquith’s Subscribe to Comments plugin version 2.3.1 or older. No other products or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, but the lack of an EPSS value means exact exploitation likelihood is uncertain. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could exploit the issue through crafted comment or subscription links that contain malicious payloads; the flaw is likely reachable without elevated privileges, making the risk potentially higher if the plugin is widely used.
OpenCVE Enrichment