CVE-2026-92989: Unknown Sendpress Newsletters
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.
Affected products
- Unknown Sendpress Newsletters: up to and including 1.26.1.20
Published 2026-10-09. Last modified 2026-10-09.