Impact
The Simple Newsletter Plugin is vulnerable to Stored Cross‑Site Scripting through the noptin_fields[<custom_field_merge_tag>] input on the public manage_preferences form. The plugin fails to sanitize and escape user supplied data, which allows an attacker to embed arbitrary JavaScript that is stored and later executed whenever a privileged user views a campaign preview containing the injected merge tag. The injected script runs with the authority of the user accessing the page, enabling malicious actions such as defacement, credential theft, or session hijacking.
Affected Systems
Picocodes Noptin – Newsletter, New Post Notifications & Email Automation, all versions up to 4.3.10 inclusive are affected. Upgrading to version 4.4.0 or later removes the vulnerability.
Risk and Exploitability
With a CVSS score of 5.4, the flaw poses moderate risk. The exploit requires an unauthenticated POST to the public preferences form followed by a social‑engineering step in which a privileged user is convinced to open a campaign preview link that contains the injected payload. Although bounded by user interaction and social‑engineering, the vulnerability can be leveraged to gain persistent client‑side access to otherwise protected administrative sessions. No EPSS data is available and the issue is not listed in CISA KEV at this time.
OpenCVE Enrichment