Access Control Flaw in weDevs Subscribe2 Plugin by WordPress
CVE-2026-24944
6.5MEDIUM
What is CVE-2026-24944?
A vulnerability in the weDevs Subscribe2 plugin allows attackers to exploit incorrectly configured access control settings. This issue could lead to unauthorized access, enabling malicious actors to manipulate or view content they shouldn't be able to. Security levels within the plugin are not adequately enforced, making it essential for users to review and adjust their settings to prevent potential exploitation. This vulnerability affects Subscribe2 versions n/a through 10.44, necessitating prompt attention from site administrators.
Affected Version(s)
Subscribe2 0 <= 10.44