plugin

Subscribe To Category Vulnerabilities

5 known security issues reported for the Subscribe To Category WordPress plugin. Most recent disclosed Jan 2, 2025.

1 critical 1 medium

Running Subscribe To Category on your site? Check whether your installed version is affected.

Scan your site free

Subscribe to Category [subscribe-to-category] <= 2.7.3 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Category: from n/a through 2.7.4.

Affected:
up to 2.7.3
Fix:
No patched version reported
Disclosed:
Jan 2, 2025

CVE-2022-43476 on NVD →

Subscribe to Category [subscribe-to-category] <= 2.7.4 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.

Affected:
up to 2.7.4
Fix:
No patched version reported
Disclosed:
Dec 20, 2023

CVE-2023-32590 on NVD →

Subscribe to Category [subscribe-to-category] <= 2.7.4 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Category: from n/a through 2.7.4.

Affected:
up to 2.7.4
Fix:
No patched version reported
Disclosed:
Nov 6, 2023

CVE-2023-38382 on NVD →

Subscribe to Category <= 2.7.4 - Unauthenticated SQL Injection

critical

The Subscribe to Category plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
9.8
Affected:
up to 2.7.4
Fix:
No patched version reported
Disclosed:
Jul 20, 2023

CVE-2023-32590 on NVD →

Subscribe to Category <= 2.7.3 - Missing Authorization

medium

The Subscribe to Category plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke them leading to Information Expos...

CVSS:
5.4
Affected:
up to 2.7.3
Fix:
No patched version reported
Disclosed:
Oct 31, 2022

CVE-2022-43476 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database