PT-2026-81971 · WordPress · Simple Newsletter Plugin
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Newsletter Plugin versions prior to 4.3.3
Description
An issue exists where the plugin fails to verify if the requester is the subscriber specified in a public request before displaying stored details. This allows unauthenticated users to disclose a subscriber's personally identifiable information (PII) and the
confirm key used to authorize changes to their record via the Actions page.Recommendations
Update Simple Newsletter Plugin to version 4.3.3 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Newsletter Plugin