Subscribe2 Project maintains a WordPress plugin focused on newsletter and subscription management, a narrowly scoped but notably represented component in the WordPress ecosystem. The vulnerability profile centers on web-application input handling and authorization boundaries, with recurring signals in cross-site request forgery, cross-site scripting, and missing authorization checks—defects typical of user-facing web plugins where request validation and output encoding are foundational. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Subscribe2 Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6604MEDIUM Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress allows remote attackers to inject arbitrary web script or HT | Mar 29, 2018 | 6.1 | 20 | NO | NO |
The Subscribe2 WordPress plugin before 10.38 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete arbitrary users by knowing t | Jan 16, 2023 | 3.1 | 16 | NO | NO |
CVE-2023-3407MEDIUM The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.40. This is due to missing or incorrect nonce validation when s | Jun 28, 2023 | 4.3 | 14 | NO | NO |
CVE-2023-1844MEDIUM The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and in | Jun 28, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Subscribe2 Project.
Media articles that mention a CVE ID that affects a product developed by Subscribe2 Project — matched by CVE ID, not by vendor name.