What the vulnerability does
01Description
Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
What the vulnerability does
Improper Neutralization of Formula Elements in a CSV File vulnerability in Noptin Newsletter Simple Newsletter Plugin – Noptin.This issue affects Simple Newsletter Plugin – Noptin: from n/a through 1.9.5.
Explanation of Vulnerability in Simple Terms
Noptin Newsletter Plugin versions up to 1.9.5 contain an integrity vulnerability that allows an attacker to modify site content or data through a network-based attack. The vulnerability requires user interaction—typically the victim must click a malicious link or visit an attacker-controlled page. The impact extends beyond the plugin itself to affect the broader site.
What an attacker can do
Modify site content or data by tricking a user into clicking a malicious link.
Potential impact on your site
Site content or user data could be altered without authorization if a user is socially engineered.
Conditions required to exploit
Victim must click an attacker-supplied link or visit an attacker-controlled page; no authentication required.
Key dates
External resources
Related vulnerabilities