CVE-2026-91073 PUBLISHED

Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form Setting

Assigner: WPScan
Reserved: 14.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor who views a page embedding the form, including logged-out visitors and administrators.

Product Status

Vendor Unknown
Product Subscribe Forms
Versions Default: unaffected
  • affected from 1.4.1 to 1.6.3 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE