Description
The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[<custom_field_merge_tag>] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
Published: 2026-10-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Stored Cross‑Site Scripting via payload injection in subscriber preferences
Action: Apply patch
AI Analysis

Impact

The Simple Newsletter Plugin is vulnerable to Stored Cross‑Site Scripting through the noptin_fields[<custom_field_merge_tag>] input on the public manage_preferences form. The plugin fails to sanitize and escape user supplied data, which allows an attacker to embed arbitrary JavaScript that is stored and later executed whenever a privileged user views a campaign preview containing the injected merge tag. The injected script runs with the authority of the user accessing the page, enabling malicious actions such as defacement, credential theft, or session hijacking.

Affected Systems

Picocodes Noptin – Newsletter, New Post Notifications & Email Automation, all versions up to 4.3.10 inclusive are affected. Upgrading to version 4.4.0 or later removes the vulnerability.

Risk and Exploitability

With a CVSS score of 5.4, the flaw poses moderate risk. The exploit requires an unauthenticated POST to the public preferences form followed by a social‑engineering step in which a privileged user is convinced to open a campaign preview link that contains the injected payload. Although bounded by user interaction and social‑engineering, the vulnerability can be leveraged to gain persistent client‑side access to otherwise protected administrative sessions. No EPSS data is available and the issue is not listed in CISA KEV at this time.

Generated by OpenCVE AI on October 10, 2026 at 06:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Noptin to version 4.4.0 or later to remove the input sanitization flaw
  • If an upgrade cannot be performed immediately, restrict unauthenticated access to the manage_preferences endpoint or disable the use of custom field merge tags in campaign bodies via security settings
  • Monitor web application logs for unexpected POST requests to manage_preferences and for the use of suspicious noptin_fields parameters, and treat any such activity as a potential attack

Generated by OpenCVE AI on October 10, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[<custom_field_merge_tag>] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
Title Simple Newsletter Plugin <= 4.3.10 - Unauthenticated Stored Cross-Site Scripting via Subscriber Custom Field via Manage Preferences Form + Campaign Preview noptin_key Pivot
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:31:05.867Z

Reserved: 2026-09-30T16:24:35.468Z

Link: CVE-2026-103482

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:36.887

Modified: 2026-10-10T06:16:36.887

Link: CVE-2026-103482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')