CVE-2026-92989: SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing
The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with subscriber-level access can exploit the affected newsletter-management actions. An attacker does not need an administrative or editor role.
What could an attacker do with the vulnerable actions?
They can synchronise all site users into a mailing list and drive the newsletter send queue. This could expose site users to unwanted mailing-list enrollment and unauthorized newsletter processing.
Which versions are affected?
SendPress Newsletters through version 1.26.1.20 is affected. The provided information does not identify a fixed version or workaround.