Sceawere
Vulnerability Detail
CVE-2026-103482UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Noptin Stored Cross-Site Scripting
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 2h ago
- Vendor
- picocodes
- Product
- Noptin – Newsletter, New Post Notifications & Email Automation
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[<custom_field_merge_tag>] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain requires a published campaign post whose body contains a [[subscriber.*]] merge tag; the unauthenticated attacker first POSTs the entity-encoded payload to the public manage_preferences form (which issues its own nonce on the same page), then pivots execution by embedding their confirm_key in a campaign preview URL sent to a privileged user via social engineering.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-10T06:16:36.887Z",
"pubdate": "2026-10-10T06:16:36.887Z",
"executiveSummary": "The Simple Newsletter Plugin – Noptin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping. This vulnerability, present in all versions up to and including 4.3.10, allows unauthenticated remote attackers to inject malicious JavaScript into web pages rendered by the application.\nThe flaw stems from the improper handling of custom subscriber fields, specifically those mapped to merge tags such as 'noptin_fields[<custom_field_merge_tag>]'. Successful exploitation permits the execution of arbitrary scripts within the context of the victim's session, potentially leading to unauthorized actions, session hijacking, or the modification of site content.\nThe attack is characterized by its reliance on social engineering, requiring an attacker to manipulate a privileged user into interacting with a crafted campaign preview URL. While the vulnerability originates from a public-facing component, the execution phase targets authorized administrators or users. Organizations should treat this as a high-risk security flaw, particularly given the ability for unauthenticated parties to inject persistent malicious payloads into subscriber profiles.",
"technicalDetails": "The vulnerability resides within the Noptin plugin's data handling logic for custom merge tags. The plugin fails to adequately sanitize input received via the 'noptin_fields' parameter during the management of subscriber preferences, nor does it perform sufficient output escaping when rendering these fields within campaign posts.\nThe attack flow commences with an unauthenticated attacker interacting with the public 'manage_preferences' form. By submitting a crafted request containing an entity-encoded malicious JavaScript payload within a custom field (e.g., 'first_name'), the attacker successfully persists the script in the plugin's database. Because the application fails to validate the content of these fields, the injected payload remains stored and inactive until rendered in a specific context.\nThe second phase of the attack requires the presence of a published campaign post that utilizes the [[subscriber.*]] merge tag. When this tag is processed by the plugin, the application dynamically replaces it with the user-defined data stored in the database, including the malicious script injected earlier. The execution vector is triggered when an attacker baits a privileged user, such as an administrator, into accessing a campaign preview URL that embeds the attacker's 'confirm_key'.\nUpon visiting the crafted URL, the privileged user's browser processes the campaign post. The server-side rendering logic retrieves the malicious payload from the database and inserts it directly into the DOM of the preview page without proper sanitization or context-aware escaping. Consequently, the browser interprets the injected payload as executable JavaScript.\nThe impact of this XSS vulnerability is significant. Once executed, the malicious script operates within the security context of the privileged user's session. This grants the attacker the capability to perform any action the user is authorized to execute, including creating new administrative accounts, altering plugin configuration, injecting further malicious code, or exfiltrating sensitive session tokens and cookies. Given that the payload is stored persistently in the database, it remains active until the record is deleted or the malicious content is sanitized from the database, posing an ongoing threat to any privileged user who previews or views the affected campaign content."
}