Cross-site Scripting in Mail Subscribe List by Richard Leishman
CVE-2025-58018
6.5MEDIUM
What is CVE-2025-58018?
The Mail Subscribe List plugin, developed by Richard Leishman, contains a vulnerability that allows for Stored Cross-site Scripting (XSS) attacks. This occurs due to improper neutralization of input during web page generation, potentially allowing attackers to inject malicious scripts. The vulnerability affects all versions of Mail Subscribe List up to and including version 2.1.10, exposing users to risks such as data theft and unauthorized access.
Affected Version(s)
Mail Subscribe List <= 2.1.10