CVE-2026-14331: Subscribe2 < 10.46 - Reflected XSS via email Parameter
Published Aug 7, 2026
·Updated
The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, leading to Reflected Cross-Site Scripting that executes in the browser of an unauthenticated visitor who interacts with the form through a crafted link.
Affected Software
1 affected component
Subscribe2 WordPress plugin<10.46
Event History
Aug 7, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-14331?
The severity of CVE-2026-14331 is rated at 35.
2
How do I fix CVE-2026-14331?
To fix CVE-2026-14331, update the Subscribe2 plugin to version 10.46 or later.
3
What type of vulnerability is CVE-2026-14331?
CVE-2026-14331 is a Reflected Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-14331?
Users of the Subscribe2 WordPress plugin version prior to 10.46 are affected by CVE-2026-14331.
5
What can an attacker do with CVE-2026-14331?
An attacker can exploit CVE-2026-14331 to execute malicious scripts in the browser of an unauthenticated visitor through a crafted link.