Input validation vulnerability in Subscribe2 – Form, Email Subscribers & Newsletters 10.40

The Subscribe2 WordPress plugin has a security issue in versions up to and including 10.40. This vulnerability allows an unauthenticated attacker to send emails with custom content to users of sites running this vulnerable version of the plugin. This can happen if the attacker can trick a site administrator into clicking on a link. The vulnerability comes from the lack of proper validation when sending test emails.

Detected in:

Subscribe2 – Form, Email Subscribers & Newsletters fixed vulnerable versions: >= * <= 10.40

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.