CVE-2026-91829: Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter
The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue and who is at risk?
An unauthenticated attacker can craft a malicious URL. The XSS executes in the browser of a user who clicks that URL, including a WordPress administrator.
What versions are affected?
Subscribe to Comments versions earlier than 2.3.3 are affected. Version 2.3.3 or later is not identified as affected by the provided information.
What input is involved in the attack?
The attack uses the ref parameter, which is reflected into a link target without proper validation. Exploitation requires persuading a target to visit a crafted URL containing that parameter.