Unrated severityNVD Advisory· Published Oct 9, 2026
CVE-2026-92989
CVE-2026-92989
Description
The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.26.1.20
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.