CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-92990: SendPress Newsletters 0 through 1.26.1.20

Affected technology

SendPress Newsletters · 0 through 1.26.1.20
Vendor not specified by the source

Description’s affected range: through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret

Component: Not specified by the source

What an attacker can do

Unauthenticated users can read newsletter sending logs, including recipient email addresses.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-92990.html