CVE-2026-92989: Unknown Sendpress Newsletters

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.

Affected products

  • Unknown Sendpress Newsletters: up to and including 1.26.1.20

Published 2026-10-09. Last modified 2026-10-09.