Executive brief
Subscribe to Comments is a popular WordPress plugin that allows visitors to receive notifications when comments are posted on articles. A cross-site scripting (XSS) vulnerability in versions 2.3.1 and earlier allows an author-level user to inject malicious scripts that could steal visitor data or hijack user accounts. Exploitation requires a privileged author to craft and trigger the attack, typically through social engineering.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in the Subscribe to Comments WordPress plugin affecting versions 2.3.1 and earlier. The root cause stems from insufficient input sanitization or output encoding in author-controlled functionality. Attack requires author-level privileges and user interaction, such as a victim clicking a malicious link or visiting a crafted page. An attacker with author privileges can inject arbitrary JavaScript into the site, enabling account hijacking, session theft, or visitor data harvesting. No official patch has been released; upgrading to a patched version or applying security measures through a hosting provider is advised.
Affected products
- WordPress Subscribe to Comments ≤ 2.3.1
Timeline
- 2026-08-06: disclosed
- 2026-07-08: other: Vulnerability reported to Patchstack