Impact
Unauthenticated Cross Site Scripting exists in the Subscribe2 plugin for Word versions up to and including 10.46. The flaw allows an attacker to inject malicious scripts that are rendered with the privileges of the site visitor, potentially enabling phishing, cookie theft, or defacement. The weakness is a classic input validation issue listed as CWE-79.
Affected Systems
The vulnerable product is the Subscribe2 plugin developed by weDevs for WordPress, affecting all installed instances of version 10.46 or earlier.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate severity rating. Because the attack does not require authentication and can be triggered by any visitor, the risk of exploitation is significant. EPSS data is unavailable, but the absence from the CISA KEV catalog does not diminish the potential for abuse. An attacker can place malicious payloads in units that the plugin displays, compromising user sessions or defacing site content.
OpenCVE Enrichment