๐Ÿ” CVE Alert

CVE-2026-78146

MEDIUM 6.5

Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page

CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
7th

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.

Vendor unknown
Product simple newsletter plugin
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simple newsletter plugin

Be the first to know when new medium vulnerabilities affecting unknown simple newsletter plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simple Newsletter Plugin
4.0.0 < 4.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/dd6e7f9c-b986-4bb7-afb4-530a8b149605/

Credits

Shivamani Vastrala WPScan