AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14331

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Subscribe2 WordPress plugin prior to version 10.46 is vulnerable to Reflected Cross-Site Scripting (XSS) due to inadequate escaping of user-supplied input in its public subscription form. This flaw allows attackers to execute malicious scripts in the browsers of unauthenticated users who interact with the compromised form via specially crafted links. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-14331
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%
WordPress

Original NVD Description

The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.