CVE-2026-39795: WordPress SendPress Newsletters plugin <= 1.26.1.20 - SQL Injection vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
Affected Software
1 affected component
SendPress SendPress Newsletters<=1.26.1.20
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. The vector is network-accessible and requires neither user interaction nor special attack conditions.
2
What is the potential impact of successful exploitation?
The supplied severity vector indicates high confidentiality impact and low availability impact, with scope changed. Integrity impact is listed as none.
3
Which plugin versions are affected?
SendPress Newsletters versions 1.26.1.20 and earlier are identified as affected. No fixed version is provided in the available data.