CVE-2026-92990
Received Received - Intake

SendPress Newsletters Plugin Hardcoded Token Exposure

Vulnerability report for CVE-2026-92990, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: WPScan

Description

The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown SendPress Newsletters 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The SendPress Newsletters WordPress plugin up to version 1.26.1.20 uses a hardcoded token to protect a logging endpoint instead of a unique per-site secret. This allows unauthenticated users to access the logs, which may contain recipient email addresses.

Detection Guidance

Check if the SendPress plugin version 1.26.1.20 or below is installed. Inspect network traffic for requests to the logging endpoint using the hardcoded token. Look for unauthorized access to logs containing recipient email addresses.

Impact Analysis

Unauthenticated attackers could read sensitive data like recipient email addresses from the plugin's logs. This could lead to privacy breaches, spam targeting, or phishing attempts using exposed email addresses.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal data (email addresses). It could result in non-compliance penalties, data breach notifications, and reputational damage for affected organizations.

Mitigation Strategies

Update the SendPress plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Restrict access to sensitive logs and monitor for unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92990. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart