CVE-2026-91829 PUBLISHED

Subscribe to Comments < 2.3.3 - Reflected XSS via 'ref' Parameter

Assigner: WPScan
Reserved: 15.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.

Product Status

Vendor Unknown
Product Subscribe to Comments
Versions Default: unaffected
  • affected from 0 to 2.3.3 (excl.)

Credits

  • Het Kalariya finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE