CVE-2026-91073
Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators.
| Vendor | unknown |
| Product | subscribe forms |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown subscribe forms
Be the first to know when new unknown vulnerabilities affecting unknown subscribe forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Subscribe Forms
1.4.1 < 1.6.3
References
Credits
Artus KG WPScan