Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-91829
CVE-2026-91829
Description
The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.3.3
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.