CVE-2026-78146 PUBLISHED

Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page

Assigner: WPScan
Reserved: 23.08.2026 Published: 26.08.2026 Updated: 26.08.2026

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.

Product Status

Vendor Unknown
Product Simple Newsletter Plugin
Versions Default: unaffected
  • affected from 4.0.0 to 4.3.3 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE