{"id":"CVE-2026-92989","title":"The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing lis…","summary":"The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing lis…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-284"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:19.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92989","references":[{"url":"https://wpscan.com/vulnerability/771aeab9-2bd2-4d77-b3b8-9fdfb651507f/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00132,"epssPercentile":0.02407,"ingestedAt":"2026-10-09T07:28:22.267Z","slug":"CVE-2026-92989","body":"## Overview\n\nThe SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218544,"id":"CVE-2026-92989","ts":1791561813153,"field":"cvss","old":null,"new":"4.3"},{"seq":218543,"id":"CVE-2026-92989","ts":1791561813153,"field":"severity","old":"none","new":"medium"}]}