plugin

Newsletter Optin Box Vulnerabilities

4 known security issues reported for the Newsletter Optin Box WordPress plugin. Most recent disclosed Jun 12, 2025.

1 high 3 medium

Running Newsletter Optin Box on your site? Check whether your installed version is affected.

Scan your site free

Noptin <= 3.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
4.4
Affected:
up to 3.8.7
Fixed in:
4.0.0
Disclosed:
Jun 12, 2025

CVE-2025-49871 on NVD →

Noptin <= 3.4.2 - Missing Authorization to Unauthenticated Form Submission

medium

The Noptin plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient controls on the process_request() function in versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to submit on private forms.

CVSS:
5.3
Affected:
up to 3.4.2
Fixed in:
3.4.3
Disclosed:
Jul 1, 2024

CVE-2024-37456 on NVD →

Simple Newsletter Plugin – Noptin <= 1.10.3 - Unauthenticated CSV Injection

high

The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.10.3. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...

CVSS:
7.2
Affected:
up to 1.10.3
Fixed in:
1.11.0
Disclosed:
Jan 27, 2023

CVE-2022-46803 on NVD →

WordPress Newsletter Plugin – Noptin < 1.6.5 - Open Redirect

medium

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue.

CVSS:
6.1
Affected:
up to 1.6.5
Fixed in:
1.6.5
Disclosed:
Jan 17, 2022

CVE-2021-25033 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database