Junglewise Threat Intelligence

CVE-2026-91073: Subscribe Forms WordPress plugin stored XSS in form settings

CVE-2026-91073 · Severity: medium · CVSS 6.8 · Published 2026-09-23

Executive brief

The Subscribe Forms WordPress plugin before version 1.6.3 contains a stored cross-site scripting (XSS) vulnerability in its form settings. An authenticated user with Author role or higher can inject malicious scripts into form configuration that will execute in the browsers of all visitors viewing pages with the embedded form, including administrators and logged-out users. This could lead to account takeover, malware distribution, or unauthorized actions performed on behalf of victims.

Technical details

The plugin fails to sanitize and escape the Attention Effect form setting before outputting it to a page, enabling stored XSS attacks. The vulnerability requires authentication with Author role or above to inject the payload, but executes for any visitor viewing the affected page. The issue affects versions 1.4.1 through 1.6.2 and is fixed in version 1.6.3.

Affected products

  • Artus KG Subscribe Forms 1.4.1 to 1.6.2

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Fixed in version 1.6.3

References