The Mailgun Subscriptions plugin for WordPress has a stored cross-site scripting (XSS) vulnerability affecting versions up to 1.3.1. Insufficient input sanitization and output escaping in the 'mailgun_subscription_form' shortcode allows authenticated users with contributor-level access to execute arbitrary scripts.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.