Description
The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure (Recipient Email Addresses)
Action: Update Plugin
AI Analysis

Impact

A hardcoded token protected the SendPress Newsletters logging endpoint rather than a dynamic per-site secret, which allows any unauthenticated user to access logs that contain recipient email addresses. The vulnerability does not provide code execution or denial of service; its primary impact is the confidentiality breach of user contact information.

Affected Systems

WordPress sites running the SendPress Newsletters plugin version 1.26.1.20 or earlier. The plugin vendor is SendPress.

Risk and Exploitability

No EPSS or KEV data are available, and a CVSS score is not provided. However, the attack requires only a simple HTTP request to the protected endpoint, and authentication is not needed. The risk is moderate to high depending on the value of the exposed email list, as the breach could facilitate phishing or spam campaigns. An attacker can exploit the issue by browsing to the log URL with the default token and retrieving the data.

Generated by OpenCVE AI on October 9, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SendPress Newsletters plugin to a version newer than 1.26.1.20 once an official patch is released.
  • If an upgrade is not possible immediately, block unauthenticated access to the logging endpoint or the wp-admin area using web server configuration or a security plugin.
  • Continuously monitor the site’s logs and email usage for any abnormal download activity or spam incidents related to exposed email addresses.

Generated by OpenCVE AI on October 9, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 09 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.
Title SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded Token
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-09T06:00:07.524Z

Reserved: 2026-09-17T14:00:52.233Z

Link: CVE-2026-92990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T07:17:19.153

Modified: 2026-10-09T07:17:19.153

Link: CVE-2026-92990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor