Mail Subscribe List <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...
- CVSS:
- 6.4
- Affected:
- up to 2.1.10
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-58018 on NVD →
Mail Subscribe List [mail-subscribe-list] < 2.1.10 (closed)
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe List plugin <= 2.1.9 versions.
- Affected:
- up to 2.1.10
- Fixed in:
- 2.1.10
- Disclosed:
- May 16, 2023
CVE-2023-23657 on NVD →
Mail Subscribe List [mail-subscribe-list] < 2.1 (closed)
unknown
[en] A vulnerability, which was classified as problematic, has been found in Mail Subscribe List Plugin up to 2.0.10 on WordPress. This issue affects some unknown processing of the file index.php. The manipulation of the argument sml_name/sml_email leads to cross site scripting. The attack may be initiated remotely. Up...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- May 2, 2023
CVE-2013-10026 on NVD →
Mail Subscribe List <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via smlsubform shortcode
medium
The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘smlsubform’ shortcode in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inj...
- CVSS:
- 6.4
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.10
- Disclosed:
- Apr 20, 2023
CVE-2023-23657 on NVD →
Mail Subscribe List [mail-subscribe-list] < 2.1.4 (closed)
unknown
[en] The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Jun 20, 2022
CVE-2022-1603 on NVD →
Mail Subscribe List <= 2.1.3 - Cross-Site Request Forgery
high
The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed list
- CVSS:
- 8.8
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- May 26, 2022
CVE-2022-1603 on NVD →
Mail Subscribe List <= 2.1.6 - Stored Cross-Site Scripting
medium
The plugin Mail Subscribe List for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execu...
- CVSS:
- 5.4
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- May 26, 2022
Mail Subscribe List [mail-subscribe-list] < 2.1.7 (closed)
unknown
The plugin Mail Subscribe List for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execu...
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- May 26, 2022
Mail Subscribe List [mail-subscribe-list] < 2.1 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update plugin.
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- May 15, 2015
Mail Subscribe List <= 2.0.9 - Unauthenticated Stored Cross-Site Scripting
medium
The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sml_name' and 'sml_email' parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 2.0.9
- Fixed in:
- 2.1
- Disclosed:
- Aug 1, 2014
CVE-2013-10026 on NVD →
Mail Subscribe List [mail-subscribe-list] < 2.1 (closed)
unknown
The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sml_name' and 'sml_email' parameters in versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Aug 1, 2014
Mail Subscribe List [mail-subscribe-list] <= 2.1.10 (unfixed)
unknown
- Affected:
- up to 2.1.10
- Fix:
- No patched version reported
CVE-2025-58018 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database