Noptin <= 3.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 4.4
- Affected:
- up to 3.8.7
- Fixed in:
- 4.0.0
- Disclosed:
- Jun 12, 2025
CVE-2025-49871 on NVD →
Noptin <= 3.4.2 - Missing Authorization to Unauthenticated Form Submission
medium
The Noptin plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient controls on the process_request() function in versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to submit on private forms.
- CVSS:
- 5.3
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Jul 1, 2024
CVE-2024-37456 on NVD →
Simple Newsletter Plugin – Noptin <= 1.10.3 - Unauthenticated CSV Injection
high
The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.10.3. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...
- CVSS:
- 7.2
- Affected:
- up to 1.10.3
- Fixed in:
- 1.11.0
- Disclosed:
- Jan 27, 2023
CVE-2022-46803 on NVD →
WordPress Newsletter Plugin – Noptin < 1.6.5 - Open Redirect
medium
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue.
- CVSS:
- 6.1
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- Jan 17, 2022
CVE-2021-25033 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database