Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbitrary Subscription Management
medium
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any public...
- CVSS:
- 6.5
- Affected:
- up to 240119
- Fix:
- No patched version reported
- Disclosed:
- May 4, 2026
CVE-2026-4409 on NVD →
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 240119
unknown
[en] Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
- Affected:
- up to 240119
- Fixed in:
- 240119
- Disclosed:
- Apr 10, 2024
CVE-2024-31249 on NVD →
Subscribe To Comments Reloaded <= 220725 - Unauthenticated Sensitive Information Exposure
medium
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 220725 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
- CVSS:
- 5.3
- Affected:
- up to 220725
- Fixed in:
- 240119
- Disclosed:
- Apr 5, 2024
CVE-2024-31249 on NVD →
Subscribe To Comments Reloaded <= 211130 - Cross-Site Request Forgery
high
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications sett...
- CVSS:
- 8.8
- Affected:
- up to 211130
- Fixed in:
- 220502
- Disclosed:
- Apr 29, 2022
CVE-2022-29414 on NVD →
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 220502
unknown
[en] Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications...
- Affected:
- up to 220502
- Fixed in:
- 220502
- Disclosed:
- Apr 29, 2022
CVE-2022-29414 on NVD →
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/in...
- Affected:
- up to 140219
- Fixed in:
- 140219
- Disclosed:
- Mar 19, 2018
CVE-2014-2274 on NVD →
Subscribe To Comments Reloaded < 150820 - Reflected Cross-Site Scripting
medium
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘srp’ parameter in versions up to, and including, 150611 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 150820
- Fixed in:
- 150820
- Disclosed:
- Aug 20, 2015
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 150820
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 150820
- Fixed in:
- 150820
- Disclosed:
- Aug 20, 2015
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 150820
unknown
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘srp’ parameter in versions up to, and including, 150611 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- Affected:
- up to 150820
- Fixed in:
- 150820
- Disclosed:
- Aug 20, 2015
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219
unknown
This plugin is prone to a options/index.php manager_page parameter stored XSS vulnerability. It allows to perform unauthorized actions in the context of a logged-in user of the affected application.
Update the plugin.
- Affected:
- up to 140219
- Fixed in:
- 140219
- Disclosed:
- Aug 1, 2014
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219
unknown
This plugin is prone to an options/index.php admin settings manipulation CSRF vulnerability. It allows to perform unauthorized actions in the context of a logged-in user of the affected application.
Update the plugin.
- Affected:
- up to 140219
- Fixed in:
- 140219
- Disclosed:
- Aug 1, 2014
Subscribe To Comments Reloaded <= 140129 - Cross-Site Request Forgery to Cross-Site Scripting
high
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.p...
- CVSS:
- 8.8
- Affected:
- up to 140129
- Fixed in:
- 140219
- Disclosed:
- Feb 18, 2014
CVE-2014-2274 on NVD →
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 150820
unknown
The Subscribe To Comments Reloaded WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 150820
- Fixed in:
- 150820
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded] < 140219
unknown
The Subscribe To Comments Reloaded WordPress plugin was affected by an options/index.php Admin Settings Manipulation CSRF security vulnerability.
- Affected:
- up to 140219
- Fixed in:
- 140219
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database