๐Ÿ” CVE Alert

CVE-2026-91073

UNKNOWN 0.0

Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators.

Vendor unknown
Product subscribe forms
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown subscribe forms

Be the first to know when new unknown vulnerabilities affecting unknown subscribe forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Subscribe Forms
1.4.1 < 1.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/50d0d5b6-2204-4af3-92d5-75085ce2f176/

Credits

Artus KG WPScan