{
 "id": "WPSEC-2026-0589",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0589/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0589/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0589/index.md",
 "title": "Subscribe to Comments <= 2.3.1 - Unauthenticated Sensitive Information Exposure via Subscription Management Keys",
 "description": "The Subscribe to Comments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the comment subscription form and the 'subscribe without commenting' feature. This makes it possible for unauthenticated attackers to obtain the subscription-management key of another person's e-mail address and use it to manage that person's comment subscriptions.",
 "plugin": {
  "slug": "subscribe-to-comments",
  "name": "Subscribe to Comments",
  "full_name": "Subscribe to Comments",
  "wordpress_org": "https://wordpress.org/plugins/subscribe-to-comments/",
  "advisories_url": "https://wpsec.com/vuln/plugin/subscribe-to-comments/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/subscribe-to-comments"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.3.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.3.2"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.3.2",
 "remediation": "Update to 2.3.2 or later.",
 "fix_released": "2026-10-06T04:05:57+00:00",
 "published": "2026-10-07T19:47:10+00:00",
 "updated": "2026-10-07T19:15:11.569769+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0589/",
  "https://plugins.svn.wordpress.org/subscribe-to-comments/tags/2.3.2/",
  "https://wordpress.org/plugins/subscribe-to-comments/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/subscribe-to-comments",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}