CVE-2026-92990: SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded Token
Published Oct 9, 2026
·Updated
The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.
Affected Software
1 affected component
SendPress SendPress Newsletters<=1.26.1.20
Event History
Oct 9, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites running the SendPress Newsletters WordPress plugin version 1.26.1.20 or earlier are affected. The exposed data includes newsletter sending logs and recipient email addresses.
2
Does an attacker need an account or authentication?
No. The logging endpoint can be accessed by unauthenticated users because it relies on a hardcoded token shared across installations.