The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sun, 11 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators. | |
| Title | Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-11T06:00:19.131Z
Reserved: 2026-09-15T08:14:17.296Z
Link: CVE-2026-91829
No data.
Status : Received
Published: 2026-10-11T07:17:29.193
Modified: 2026-10-11T07:17:29.193
Link: CVE-2026-91829
No data.
OpenCVE Enrichment
Updated: 2026-10-11T08:00:13Z
Weaknesses