What is CVE-2026-14331?
CVE-2026-14331 is a Reflected Cross-Site Scripting vulnerability in the Subscribe2 WordPress plugin before version 10.46, caused by improper escaping of a user-supplied value before it is reflected in a public subscription form. This allows an unauthenticated visitor to execute code in their own browser by interacting with the form through a crafted link. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-14331 Subscribe2 WordPress plaginin 10.46 versiyasından əvvəlki versiyalarında istifadəçi tərəfindən təqdim edilən dəyərin düzgün escapə edilməməsi nəticəsində yaranan Reflected Cross-Site Scripting zəifliyidir. Bu zəiflik autentifikasiya olunmamış ziyarətçinin xüsusi hazırlanmış link vasitəsilə formaya müdaxilə etməsi ilə onun brauzerində kod icrasına səbəb ola bilər. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Subscribe2 plugin are affected by CVE-2026-14331?
This Reflected Cross-Site Scripting vulnerability affects all versions of the Subscribe2 WordPress plugin prior to version 10.46.
What can an attacker achieve by exploiting CVE-2026-14331?
An unauthenticated attacker can execute code in the victim's own browser by using a crafted link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.