Description
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross Site Scripting exists in the Subscribe2 plugin for Word versions up to and including 10.46. The flaw allows an attacker to inject malicious scripts that are rendered with the privileges of the site visitor, potentially enabling phishing, cookie theft, or defacement. The weakness is a classic input validation issue listed as CWE-79.

Affected Systems

The vulnerable product is the Subscribe2 plugin developed by weDevs for WordPress, affecting all installed instances of version 10.46 or earlier.

Risk and Exploitability

The CVSS base score of 7.1 indicates a moderate severity rating. Because the attack does not require authentication and can be triggered by any visitor, the risk of exploitation is significant. EPSS data is unavailable, but the absence from the CISA KEV catalog does not diminish the potential for abuse. An attacker can place malicious payloads in units that the plugin displays, compromising user sessions or defacing site content.

Generated by OpenCVE AI on August 18, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Subscribe2 plugin to the latest version (10.47 or newer).
  • If upgrading is not immediately possible, disable or uninstall the plugin to prevent exploitation.
  • Deploy a Web Application Firewall or similar filtering mechanism to detect and block XSS payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on August 18, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Wedevs
Wedevs subscribe2
Wordpress
Wordpress wordpress
Vendors & Products Wedevs
Wedevs subscribe2
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Title WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wedevs Subscribe2
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:11:14.154Z

Reserved: 2026-08-12T14:10:08.047Z

Link: CVE-2026-73393

cve-icon Vulnrichment

Updated: 2026-08-18T14:59:39.484Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:06.687

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')