CVE-2026-92990 PUBLISHED

SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded Token

Assigner: WPScan
Reserved: 17.09.2026 Published: 09.10.2026 Updated: 09.10.2026

The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.

Product Status

Vendor Unknown
Product SendPress Newsletters
Versions Default: unknown
  • affected from 0 to 1.26.1.20 (incl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE