Security Alert Summary
The SendPress Newsletters plugin through version 1.26.1.20 exposes a logging endpoint that is protected by a hardcoded token shared across installations rather than a per-site secret. This allows unauthenticated users to read newsletter sending logs, which can include recipient email addresses.
CVE Details
- CVE ID:
CVE-2026-92990 - Affected product: SendPress Newsletters
- Affected versions: Versions up to and including 1.26.1.20
- Published: October 9, 2026 at 7:17:19 AM
- Last modified: October 9, 2026 at 3:17:19 PM
- CVSS v3.1 base score: 5.3 (MEDIUM)
- CVSS v3.1 vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - Authentication / privileges / user interaction: No authentication required; privileges required: none; user interaction: none
- Primary impact: Confidentiality: Low; Integrity: None; Availability: None
- CWE / weakness: CWE-200 (Information Exposure)
Technical Details
The plugin protects a logging endpoint using a hardcoded token that is identical across sites instead of using a per-site secret. Because the token is the same on every installation, an attacker can present that token and read the newsletter sending logs without authenticating to the site.
The exposed logs can include recipient email addresses and other information recorded by the plugin’s logging facility. The vulnerability exists due to the use of a static token value for access control rather than generating and validating a secret unique to each installation or tying access to authenticated user capabilities.
How This Could Impact Your Website
Consider a small organization where the site owner manages the site, an internal staff member composes newsletters, and an external contractor helps with content. If the plugin logs newsletter activity and that logging endpoint is accessible using the shared hardcoded token, an unauthenticated third party could retrieve recent mailing logs and harvest recipient email addresses.
Practical consequences include exposure of internal or subscriber email addresses and an increased risk of targeted phishing or social engineering against staff or subscribers. The issue does not, based on the available data, imply modification of site content or denial of service, but it does raise privacy and targeted-email risks.
If you’re unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review your setup.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially contributor-level accounts and other roles with publishing or content access.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins to reduce your attack surface.
- Monitor site activity and access logs for unusual requests to plugin endpoints or unexpected data downloads.
If you’d like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.