Subscribe2
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Subscribe2. Use it to gauge the current risk picture and drill into individual advisories.
Subscribe2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium4
- Low1
Latest CVEs
The 6 most recently published vulnerabilities affecting Subscribe2.
- CVE-2026-73393WordPress Subscribe2 plugin <= 10.46 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-24944WordPress Subscribe2 plugin <= 10.44 - Broken Access Control vulnerability6.5
- CVE-2023-1844Subscribe2 <= 10.40 - Missing Authorization4.3
- CVE-2023-3407Subscribe2 <= 10.40 - Cross-Site Request Forgery4.3
- CVE-2022-4309Subscribe2 < 10.38 - User Deletion via CSRF3.1
- CVE-2014-6604Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ip par...6.1
Product grouping is registry-driven, with AI assist and human review. How it works