Subscribe to Comments <= 2.3.1 - Authenticated (Author+) Missing Authorization to Plugin Settings Update

Medium 6.4 CWE-862Fixed in 2.3.2
ID
WPSEC-2026-0590
Plugin
Subscribe to Comments (subscribe-to-comments)
Affected
all versions before 2.3.2
Remediation
Update to 2.3.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Subscribe to Comments on WPSec AttackSurface
Fix released
Published

Description

The Subscribe to Comments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on its settings page in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Author-level access and above, to change the plugin's settings, including injecting scripts into the comment form text and setting the secret used to generate subscription-management keys.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0