UNKNOWN (0.0)
    Plugin

    Mailgun Subscriptions Plugin Stored Cross-Site Scripting Vulnerability

    Published Date: 12/12/2025
    CVE ID: CVE-2025-11876

    Summary

    The Mailgun Subscriptions plugin for WordPress has a stored cross-site scripting (XSS) vulnerability affecting versions up to 1.3.1. Insufficient input sanitization and output escaping in the 'mailgun_subscription_form' shortcode allows authenticated users with contributor-level access to execute arbitrary scripts.

    Vulnerability Details

    This vulnerability exists within the Mailgun Subscriptions plugin due to the lack of proper sanitization and escaping of user inputs within the 'mailgun_subscription_form' shortcode. Authenticated users with contributor-level access or higher can exploit this flaw by injecting malicious scripts. When these scripts are embedded within a page, they execute each time the page is viewed by any user, potentially leading to session hijacking, defacement, or broader website compromise. The risk is particularly concerning for sites with multiple users with content editing privileges, as even lower-level users can leverage this flaw to execute scripts. Proper sanitization should scrub user inputs of potentially harmful characters or code, and output should be escaped before rendering in a browser to ensure safe execution.

    Recommendations

    To mitigate this vulnerability, restrict access of contributor-level accounts, ensuring only trusted and vetted users have access to edit content containing the 'mailgun_subscription_form' shortcode. Implement a regular review process to audit plugin usage and permissions. Additionally, apply a web application firewall (WAF) to filter out potential malicious script inputs.

    Available Fixes

    Last Updated: 12/13/2025
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2025 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More