Subscribe to Comments
Subscribe to Comments has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2006 and 2026; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include PHP Remote File Inclusion.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
3 independent researchers contributed these findings, one record each. Subscribe to Comments is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.3.34.
CVE-2026-66706Subscribe to Comments <= 2.3.1 - Authenticated (Author+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Subscribe to Comments
Author
Mark Jaquith
Subscribe to Comments is a robust plugin that enables commenters to sign up for e-mail notification of subsequent entries. The plugin includes a full-featured subscription manager that your commenters can use to unsubscribe to certain posts, block all notifications, or even change their notification e-mail address!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C