Missing Authorization vulnerability in brewlabs SendPress Newsletters sendpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendPress Newsletters: from n/a through <= 1.26.1.20.
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.