Subscribe to Comments <= 2.3.2 - Authenticated (Subscriber+) Incorrect Authorization to Subscription Takeover via Unverified Account Email

Medium 5.4 CWE-863Fixed in 2.3.3
ID
WPSEC-2026-0602
Plugin
Subscribe to Comments (subscribe-to-comments)
Affected
all versions before 2.3.3
Remediation
Update to 2.3.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-863
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Subscribe to Comments on WPSec AttackSurface
Fix released
Published

Description

The Subscribe to Comments plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.3.2 due to the plugin treating a user's unverified account e-mail address as proof of ownership of that address. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the subscription-management link of another person's e-mail address and manage that person's comment subscriptions.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0