plugin

Mail Subscribe List Vulnerabilities

12 known security issues reported for the Mail Subscribe List WordPress plugin. Most recent disclosed Sep 22, 2025.

1 high 4 medium

Running Mail Subscribe List on your site? Check whether your installed version is affected.

Scan your site free

Mail Subscribe List <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 2.1.10
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-58018 on NVD →

Mail Subscribe List [mail-subscribe-list] < 2.1.10 (closed)

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe List plugin <= 2.1.9 versions.

Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
May 16, 2023

CVE-2023-23657 on NVD →

Mail Subscribe List [mail-subscribe-list] < 2.1 (closed)

unknown

[en] A vulnerability, which was classified as problematic, has been found in Mail Subscribe List Plugin up to 2.0.10 on WordPress. This issue affects some unknown processing of the file index.php. The manipulation of the argument sml_name/sml_email leads to cross site scripting. The attack may be initiated remotely. Up...

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
May 2, 2023

CVE-2013-10026 on NVD →

Mail Subscribe List <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via smlsubform shortcode

medium

The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘smlsubform’ shortcode in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inj...

CVSS:
6.4
Affected:
up to 2.1.9
Fixed in:
2.1.10
Disclosed:
Apr 20, 2023

CVE-2023-23657 on NVD →

Mail Subscribe List [mail-subscribe-list] < 2.1.4 (closed)

unknown

[en] The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Jun 20, 2022

CVE-2022-1603 on NVD →

Mail Subscribe List <= 2.1.3 - Cross-Site Request Forgery

high

The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list

CVSS:
8.8
Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
May 26, 2022

CVE-2022-1603 on NVD →

Mail Subscribe List <= 2.1.6 - Stored Cross-Site Scripting

medium

The plugin Mail Subscribe List for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execu...

CVSS:
5.4
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
May 26, 2022

Mail Subscribe List [mail-subscribe-list] < 2.1.7 (closed)

unknown

The plugin Mail Subscribe List for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execu...

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
May 26, 2022

Mail Subscribe List [mail-subscribe-list] < 2.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
May 15, 2015

Mail Subscribe List <= 2.0.9 - Unauthenticated Stored Cross-Site Scripting

medium

The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sml_name' and 'sml_email' parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 2.0.9
Fixed in:
2.1
Disclosed:
Aug 1, 2014

CVE-2013-10026 on NVD →

Mail Subscribe List [mail-subscribe-list] < 2.1 (closed)

unknown

The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sml_name' and 'sml_email' parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Aug 1, 2014

Mail Subscribe List [mail-subscribe-list] <= 2.1.10 (unfixed)

unknown
Affected:
up to 2.1.10
Fix:
No patched version reported

CVE-2025-58018 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database