CVE-2026-78146: Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page
Published Aug 26, 2026
·Updated
The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.
Affected Software
1 affected component
— Simple Newsletter Plugin (WordPress plugin)<4.3.3
Event History
Aug 26, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated user can exploit it because the affected plugin does not verify that the requester is the subscriber whose public request is being viewed.
2
What information can be exposed?
An attacker can disclose a subscriber's stored personal data and the confirm_key that authorizes changes to that subscriber's record.
3
Which versions are affected?
Versions of the Simple Newsletter Plugin before 4.3.3 are affected.