Impact
A hardcoded token protected the SendPress Newsletters logging endpoint rather than a dynamic per-site secret, which allows any unauthenticated user to access logs that contain recipient email addresses. The vulnerability does not provide code execution or denial of service; its primary impact is the confidentiality breach of user contact information.
Affected Systems
WordPress sites running the SendPress Newsletters plugin version 1.26.1.20 or earlier. The plugin vendor is SendPress.
Risk and Exploitability
No EPSS or KEV data are available, and a CVSS score is not provided. However, the attack requires only a simple HTTP request to the protected endpoint, and authentication is not needed. The risk is moderate to high depending on the value of the exposed email list, as the breach could facilitate phishing or spam campaigns. An attacker can exploit the issue by browsing to the log URL with the default token and retrieving the data.
OpenCVE Enrichment