Impact
The SendPress Newsletters plugin fails to verify user capabilities for several management actions, enabling any authenticated user with subscriber privileges to synchronise all site users into a mailing list and to trigger the newsletter send queue. This flaw permits an attacker who can log in as a subscriber to inject arbitrary users into a mailing list and cause the plugin to dispatch newsletters to those addresses, potentially resulting in spam, phishing, or data exfiltration. The weakness stems from improper access control.
Affected Systems
WordPress sites using the SendPress Newsletters plugin version 1.26.1.20 or earlier. No specific vendor product names beyond the plugin are identified.
Risk and Exploitability
The vulnerability is exploitable without additional conditions beyond authentication as a subscriber. Its exploitation could lead to mass email distribution and potential compromise of recipients. No CVSS score is provided and the EPSS score is unavailable, but the lack of capability checks suggests a high likelihood of potential abuse once the plugin is widely deployed. The issue is not listed in the CISA KEV catalog, yet its impact on email systems and reputational risk warrants urgency.
OpenCVE Enrichment