CVE-2026-78146

Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.


We have discovered 770 live websites that are affected by CVE-2026-78146.

Run a Free Instant Scan




Affected Software

Product  Newsletter Optin Box
Category Wordpress Plugins
Vulnerable Domains770 live websites (67% of Newsletter Optin Box install base)
Vulnerable Versions
  • from 4 through 4.3.3
Vulnerable Versions Count27 versions ( 49% of all versions)


Common Weakness Enumeration

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • Shivamani Vastrala (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-78146
United States228 websites



Poland86 websites
Germany75 websites
France70 websites
GB39 websites
Brazil18 websites
Cyprus18 websites
India16 websites
Netherlands15 websites
Italy14 websites

Website Distribution by TLD

Number of websites using CVE-2026-78146
.com311 websites
.pl80 websites
.de49 websites
.org44 websites
.fr21 websites
.net20 websites
.co.uk20 websites
.com.br18 websites
.it10 websites
.nl10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-78146

Top websites that are affected by CVE-2026-78146. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.org Cyprus***,***
**********.com United States***,***
****************.org GB***,***
******************.com United States***,***
************.ngo United States***,***
***************.***********.com India***,***
***********.com GB***,***
******.com United States***,***
*****.org United States***,***
*******.ro United States***,***
See full domain list

FAQ

CVE-2026-78146 is Exposure of Sensitive Information to an Unauthorized Actor in Newsletter Optin Box
A total of 770 websites have been identified as vulnerable to CVE-2026-78146, based on global website indexing conducted by WebTechSurvey.
The Newsletter Optin Box is affected by the CVE-2026-78146 vulnerability.
Newsletter Optin Box versions up to 4.3.3 are vulnerable to CVE-2026-78146.
CVE-2026-78146 is resolved in version 4.3.3 of Newsletter Optin Box.