Subscribe to Comments

Subscribe to Comments has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2006 and 2026; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include PHP Remote File Inclusion.

3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

3 independent researchers contributed these findings, one record each. Subscribe to Comments is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.3.34.

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage75%
Open

1

Fixed

3

Get automatic notifications for all Subscribe to Comments vulnerabilities before they are exploited.

Most severe open issueCVSS 5.4CVE-2026-66706

Subscribe to Comments <= 2.3.1 - Authenticated (Author+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

4 records
Plugin Profile
Latestv2.3.1

Subscribe to Comments

Mark Jaquith

Author

Mark Jaquith

3.9(14)
78/100
Last Updated
2024-10-29 (2y ago)
Active Installs
10,000+
Downloads
574,771
Requires WP
2.9+
Requires PHP
0+
Tested up to
WP 4.3.34
Created
2005-06-09 (22y ago)

Subscribe to Comments is a robust plugin that enables commenters to sign up for e-mail notification of subsequent entries. The plugin includes a full-featured subscription manager that your commenters can use to unsubscribe to certain posts, block all notifications, or even change their notification e-mail address!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C