Impact
The Simple Newsletter Plugin in WordPress versions below 4.3.3 fails to confirm that the requester matches the subscriber referenced in a public request. As a result, any visitor can trigger the plugin’s actions page and receive a subscriber’s personal data along with the confirm_key that authorises changes to that subscriber’s record. This flaw is a confidentiality vulnerability (CWE‑200) that exposes sensitive personally identifiable information and grants an attacker the ability to modify subscriber data, leading to privacy violations and potential unauthorized alterations of subscriber information.
Affected Systems
WordPress sites that have the Simple Newsletter Plugin (also known as Noptin) installed with a version less than 4.3.3 are vulnerable. The flaw applies to all installations of the plugin where the version prefix is lower than the patched release, regardless of other WordPress configuration settings.
Risk and Exploitability
An attacker can exploit this issue remotely by accessing the plugin’s actions page without authentication. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The severity is medium, with a CVSS score of 6.5, and the absence of authentication requirements and straightforward request path underscore the potential for compromise, exposing subscriber personal data and enabling modification via the disclosed confirm_key.
OpenCVE Enrichment