CVE-2026-78146
Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page
CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
7th
The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.
| Vendor | unknown |
| Product | simple newsletter plugin |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown simple newsletter plugin
Be the first to know when new medium vulnerabilities affecting unknown simple newsletter plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Simple Newsletter Plugin
4.0.0 < 4.3.3
References
Credits
Shivamani Vastrala WPScan