CyberRota Analysis
AI-GeneratedThe Subscribe2 WordPress plugin prior to version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS) due to inadequate escaping of user-supplied input in its public subscription form. This flaw allows attackers to execute malicious scripts in the browsers of unauthenticated users who interact with the compromised form via specially crafted links. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.