Junglewise Threat Intelligence

CVE-2026-66706: Subscribe to Comments Author XSS in WordPress plugin

CVE-2026-66706 · Severity: medium · CVSS 5.9 · Published 2026-08-06

Vendors: Wordpress.

Executive brief

Subscribe to Comments is a popular WordPress plugin that allows visitors to receive notifications when comments are posted on articles. A cross-site scripting (XSS) vulnerability in versions 2.3.1 and earlier allows an author-level user to inject malicious scripts that could steal visitor data or hijack user accounts. Exploitation requires a privileged author to craft and trigger the attack, typically through social engineering.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in the Subscribe to Comments WordPress plugin affecting versions 2.3.1 and earlier. The root cause stems from insufficient input sanitization or output encoding in author-controlled functionality. Attack requires author-level privileges and user interaction, such as a victim clicking a malicious link or visiting a crafted page. An attacker with author privileges can inject arbitrary JavaScript into the site, enabling account hijacking, session theft, or visitor data harvesting. No official patch has been released; upgrading to a patched version or applying security measures through a hosting provider is advised.

Affected products

  • WordPress Subscribe to Comments ≤ 2.3.1

Timeline

  • 2026-08-06: disclosed
  • 2026-07-08: other: Vulnerability reported to Patchstack

References