CVE-2023-1844: SUBSCRIBE2 Project SUBSCRIBE2

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The Subscribe2 plugin for WordPress is vulnerable to unauthorized access to email functionality due to a missing capability check when sending test emails in versions up to, and including, 10.40. This makes it possible for author-level attackers to send emails with arbitrary content and attachments to site users.

Affected products

Published 2023-06-28. Last modified 2026-06-17.