Noptin < 1.6.5 is susceptible to an open redirect vulnerability. The plugin does not validate the "to" parameter before redirecting the user to its given value, leading to an open redirect issue.
id: CVE-2021-25033
info:
name: Noptin < 1.6.5 - Open Redirect
author: dhiyaneshDk
severity: m
...