First published: Mon May 02 2022(Updated: )
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
MyThemeShop WP Subscribe | <1.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36844 refers to an authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in the MyThemeShop WP Subscribe plugin version 1.2.12 and below on WordPress.
CVE-2021-36844 has a severity rating of medium with a CVSS score of 4.8.
CVE-2021-36844 allows authenticated users with admin+ privileges to execute malicious scripts on the affected plugin.
To fix CVE-2021-36844, users should update MyThemeShop WP Subscribe plugin to version 1.2.13 or newer.
You can find more information about CVE-2021-36844 on the Patchstack vulnerability database and the official WordPress plugin page for WP Subscribe.