Known vulnerabilities in Mail Subscribe List
Simple customizable plugin that displays a name/email form where visitors can submit their information, manageable in the WordPress admin.
5Reported vulnerabilities
6.4Highest CVSS score
2.1.10Latest version
3,000+Active installs
What to do now
Update Mail Subscribe List to 2.1 or later.
4 of these have a fixed version available. Updating resolves them.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-1603 | Medium | 0.4% | Before 2.1.4 | 2.1.4 |
June 20, 2022 |
| CVE-2025-58018 | Medium | 0.3% | 2.1.10 and earlier | — | September 22, 2025 |
| CVE-2023-23657 | Medium | 0.4% | 2.1.9 and earlier | 2.1.10 |
April 20, 2023 |
| CVE-2013-10026 | Medium | 0.6% | 2.0.0 to 2.0.10 (inclusive) | 2.1 |
May 2, 2023 |
| WF-75424878-5976-4dc6-8a09-8eb46a7425b8 | Medium | — | 2.1.6 and earlier | 2.1.7 |
May 26, 2022 |