๐Ÿ” CVE Alert

CVE-2026-92990

UNKNOWN 0.0

SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded Token

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.

Vendor unknown
Product sendpress newsletters
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown sendpress newsletters

Be the first to know when new unknown vulnerabilities affecting unknown sendpress newsletters are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / SendPress Newsletters
0 โ‰ค 1.26.1.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/595c6a6b-d346-4ed4-9a4e-674d90a35e74/

Credits

Usama Arshad WPScan