Sceawere

Vulnerability Detail

CVE-2026-91829UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Subscribe to Comments Reflected XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
8h ago
Vendor
Unknown
Product
Subscribe to Comments
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-11T07:17:29.193Z",
  "pubdate": "2026-10-11T07:17:29.193Z",
  "executiveSummary": "The Subscribe to Comments WordPress plugin, specifically versions prior to 2.3.3, contains a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper input validation of a parameter before it is dynamically reflected into a link target within the application.\nSuccessful exploitation allows an unauthenticated attacker to execute arbitrary client-side scripts within the context of a victim's browser session. By crafting a malicious URL containing a malicious payload, an attacker can target various users, including administrative accounts with elevated privileges.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the affected WordPress site, as injected scripts can be used to hijack sessions, steal cookies, redirect users, or perform unauthorized actions on behalf of the victim. The attack requires the victim to click the maliciously crafted URL, making social engineering a primary vector for exploitation. Since the vulnerability resides within the plugin's core functionality, all sites running versions prior to 2.3.3 remain susceptible to this unauthenticated attack vector.",
  "technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) flaw occurring within the Subscribe to Comments WordPress plugin. The root cause is an insufficient sanitization and validation mechanism applied to a user-supplied input parameter that is subsequently rendered directly into the HTML response as a link target attribute.\nIn web application security, reflected XSS occurs when an application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. In this specific case, the plugin fails to enforce strict allow-listing or context-aware output encoding on the vulnerable parameter. When an attacker crafts a URL containing a malicious JavaScript payload in the susceptible parameter, the application processes this input and reflects the payload back into the HTML document provided to the browser.\nThe attack flow proceeds as follows: First, the attacker identifies the vulnerable parameter within the plugin's URL structure. Second, the attacker generates a malicious URL that embeds a JavaScript payload (e.g., <script>alert(document.cookie)</script>) encoded for URI transport. Third, the attacker distributes this link to a target user, often utilizing social engineering tactics to encourage the target—such as an administrator—to click the link. Fourth, upon clicking, the victim's browser requests the URL from the server. Fifth, the server-side code reflects the attacker-supplied malicious string directly into the generated link target of the WordPress page. Finally, the victim's browser, interpreting the reflected input as legitimate content, executes the injected JavaScript script within the security context of the victim's active session.\nBecause the payload executes in the victim's browser, the attacker can leverage the victim’s existing authentication state to perform unauthorized actions. For an administrator target, this could involve creating new administrative users, modifying plugin settings, or installing malicious modules. The exploit does not require the attacker to have prior authentication; it is entirely unauthenticated from the perspective of the application, relying purely on the execution of the reflected payload. The lack of output encoding ensures that any characters normally reserved by HTML, such as quotes or brackets, are rendered executable, facilitating complete cross-site scripting bypasses."
}
CVE-2026-91829: Subscribe to Comments Reflected XSS (HIGH Severity, CVSS: 7.1) | Sceawere