Security Flaw in SendPress Newsletters Plugin for WordPress
CVE-2026-92989
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 October 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-92989?
The SendPress Newsletters plugin for WordPress fails to adequately restrict user capabilities when managing newsletters. Authenticated users with subscriber-level access can exploit this oversight, allowing them to synchronize all site users into a mailing list and manipulate the newsletter sending queue. This could lead to unauthorized distribution of content and potential breaches of user privacy.
Affected Version(s)
SendPress Newsletters 0 <= 1.26.1.20
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.