plugin

Subscribe To Comments Reloaded Vulnerabilities

14 known security issues reported for the Subscribe To Comments Reloaded WordPress plugin. Most recent disclosed May 4, 2026.

2 high 3 medium

Running Subscribe To Comments Reloaded on your site? Check whether your installed version is affected.

Scan your site free

Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription Management

medium

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any public...

CVSS:
6.5
Affected:
up to 240119
Fix:
No patched version reported
Disclosed:
May 4, 2026

CVE-2026-4409 on NVD →

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 240119

unknown

[en] Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

Affected:
up to 240119
Fixed in:
240119
Disclosed:
Apr 10, 2024

CVE-2024-31249 on NVD →

Subscribe To Comments Reloaded <= 220725 - Unauthenticated Sensitive Information Exposure

medium

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 220725 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log files.

CVSS:
5.3
Affected:
up to 220725
Fixed in:
240119
Disclosed:
Apr 5, 2024

CVE-2024-31249 on NVD →

Subscribe To Comments Reloaded <= 211130 - Cross-Site Request Forgery

high

Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications sett...

CVSS:
8.8
Affected:
up to 211130
Fixed in:
220502
Disclosed:
Apr 29, 2022

CVE-2022-29414 on NVD →

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 220502

unknown

[en] Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications...

Affected:
up to 220502
Fixed in:
220502
Disclosed:
Apr 29, 2022

CVE-2022-29414 on NVD →

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/in...

Affected:
up to 140219
Fixed in:
140219
Disclosed:
Mar 19, 2018

CVE-2014-2274 on NVD →

Subscribe To Comments Reloaded < 150820 - Reflected Cross-Site Scripting

medium

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘srp’ parameter in versions up to, and including, 150611 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 150820
Fixed in:
150820
Disclosed:
Aug 20, 2015

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 150820

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 150820
Fixed in:
150820
Disclosed:
Aug 20, 2015

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 150820

unknown

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘srp’ parameter in versions up to, and including, 150611 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 150820
Fixed in:
150820
Disclosed:
Aug 20, 2015

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219

unknown

This plugin is prone to a options/index.php manager_page parameter stored XSS vulnerability. It allows to perform unauthorized actions in the context of a logged-in user of the affected application. Update the plugin.

Affected:
up to 140219
Fixed in:
140219
Disclosed:
Aug 1, 2014

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219

unknown

This plugin is prone to an options/index.php admin settings manipulation CSRF vulnerability. It allows to perform unauthorized actions in the context of a logged-in user of the affected application. Update the plugin.

Affected:
up to 140219
Fixed in:
140219
Disclosed:
Aug 1, 2014

Subscribe To Comments Reloaded <= 140129 - Cross-Site Request Forgery to Cross-Site Scripting

high

Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.p...

CVSS:
8.8
Affected:
up to 140129
Fixed in:
140219
Disclosed:
Feb 18, 2014

CVE-2014-2274 on NVD →

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 150820

unknown

The Subscribe To Comments Reloaded WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 150820
Fixed in:
150820

Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219

unknown

The Subscribe To Comments Reloaded WordPress plugin was affected by an options/index.php Admin Settings Manipulation CSRF security vulnerability.

Affected:
up to 140219
Fixed in:
140219

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database