rootpwn

high · CVSS v3 6.8 · EPSS 0.00216

CVE-2026-91073

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputtin…

Description

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators.

Scores

Severity
high
CVSS v2
8.3
CVSS v3
6.8
CVSS v4
EPSS
0.00216

← All CVEs