Back

MEDIUM

Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting

Published Sep 23, 2026

Description

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 23, 2026
Updated Sep 23, 2026
Reserved Sep 14, 2026
CISA Vulnrichment
Updated Sep 23, 2026
NVD
Status Deferred
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a