Junglewise Threat Intelligence

CVE-2026-24554: Convers Lab WPSubscription CSRF in WordPress plugin

CVE-2026-24554 · Severity: medium · CVSS 4.3 · Published 2026-05-25

Executive brief

Convers Lab WPSubscription is a WordPress plugin used to manage email subscriptions and newsletters. A security flaw allows an attacker to trick a website administrator into performing unintended actions, such as changing settings or deleting data, by clicking a malicious link. This could lead to unauthorized configuration changes or disruption of the subscription service.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Convers Lab WPSubscription plugin for WordPress (versions <= 1.9.1) due to insufficient validation of request origins or missing nonce tokens. An unauthenticated remote attacker can exploit this by crafting a malicious web page or link and tricking a logged-in administrator or privileged user into interacting with it. Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the victim user, such as modifying plugin settings. The issue is addressed in version 1.9.2.

Affected products

  • Convers Lab WPSubscription n/a through 1.9.1

Timeline

  • 2025-12-23: other: Reported by researcher theviper17
  • 2026-05-25: disclosed: Published by Patchstack
  • 2026-05-25: patched: Fixed in version 1.9.2

References