CVE-2026-78146
Received Received - Intake

Unauthenticated Information Disclosure in Simple Newsletter WordPress Plugin

Vulnerability report for CVE-2026-78146, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simple_newsletter_plugin simple_newsletter_plugin to 4.3.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Simple Newsletter Plugin (WordPress) before version 4.3.3 allows unauthenticated users to access and disclose a subscriber's personal data, including the key used to authorize changes to their record. The plugin fails to verify if the requester is the actual subscriber before rendering their details.

Detection Guidance

Check if the Simple Newsletter Plugin or Noptin plugin is installed and verify its version. If it is version 4.3.3 or lower, the system is vulnerable. Look for unauthorized access to subscriber data or unusual requests to subscriber endpoints.

Impact Analysis

Unauthenticated attackers can view subscribers' personal information and obtain authorization keys, potentially leading to unauthorized data exposure or account modifications. This compromises user privacy and could enable further attacks.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized disclosure of personally identifiable information (PII) and sensitive data exposure. It could result in non-compliance penalties and legal consequences for organizations using the affected plugin.

Mitigation Strategies

Update the Simple Newsletter Plugin or Noptin plugin to version 4.3.3 or higher immediately. If updating is not possible, consider disabling the plugin temporarily until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78146. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart