PT-2023-9859 · WordPress · Subscribe To Comments Plugin

Mustlive

·

Published

2023-03-05

·

Updated

2024-11-12

·

CVE-2006-10001

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Subscribe to Comments Plugin versions up to 2.0.7
Description A problematic vulnerability was found in the Subscribe to Comments Plugin, affecting an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting and can be initiated remotely.
Recommendations For versions up to 2.0.7, upgrade to version 2.0.8 to address this issue. As a temporary workaround, consider restricting access to the affected subscribe-to-comments.php file until the upgrade is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2006-10001

Affected Products

Subscribe To Comments Plugin