Noptin is a narrowly scoped email marketing and newsletter plugin centered on a single product, where the observed vulnerability exposure centers on application-layer input handling and redirects, specifically improper neutralization of formula elements in CSV exports and open-redirect conditions. These weakness classes reflect the plugin's role in handling user-supplied marketing data and managing external link handling in email workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Noptin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25033MEDIUM The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue | Feb 14, 2022 | 6.1 | 32 | NO | YES |
CVE-2022-46803CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: | Nov 7, 2023 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Noptin.
Media articles that mention a CVE ID that affects a product developed by Noptin — matched by CVE ID, not by vendor name.