CVE-2021-36844: WordPress WP Subscribe plugin <= 1.2.12 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published May 2, 2022
·Updated
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
Affected Software
1 affected component
MyThemeShop Wp Subscribe Wordpress<1.2.13
Event History
May 2, 2022
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36844?
CVE-2021-36844 refers to an authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in the MyThemeShop WP Subscribe plugin version 1.2.12 and below on WordPress.
2
How severe is CVE-2021-36844?
CVE-2021-36844 has a severity rating of medium with a CVSS score of 4.8.
3
How does CVE-2021-36844 affect MyThemeShop WP Subscribe plugin?
CVE-2021-36844 allows authenticated users with admin+ privileges to execute malicious scripts on the affected plugin.
4
What is the fix for CVE-2021-36844?
To fix CVE-2021-36844, users should update MyThemeShop WP Subscribe plugin to version 1.2.13 or newer.
5
Where can I find more information about CVE-2021-36844?
You can find more information about CVE-2021-36844 on the Patchstack vulnerability database and the official WordPress plugin page for WP Subscribe.