CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-92989: SendPress Newsletters 0 through 1.26.1.20

Affected technology

SendPress Newsletters · 0 through 1.26.1.20
Vendor not specified by the source

Description’s affected range: through 1.26.1.20 does not check the user's capability on several newsletter-management actions

Component: Not specified by the source

What an attacker can do

Any authenticated subscriber-level user can synchronise all site users into a mailing list and to drive the newsletter send queue.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-92989.html