The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 |
Fri, 09 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses. | |
| Title | SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded Token | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-09T06:00:07.524Z
Reserved: 2026-09-17T14:00:52.233Z
Link: CVE-2026-92990
No data.
Status : Received
Published: 2026-10-09T07:17:19.153
Modified: 2026-10-09T07:17:19.153
Link: CVE-2026-92990
No data.
OpenCVE Enrichment
Updated: 2026-10-09T07:30:18Z
Weaknesses
No weakness.