{"id":"CVE-2026-92990","title":"The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs,…","summary":"The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs,…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-200"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:19.967","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92990","references":[{"url":"https://wpscan.com/vulnerability/595c6a6b-d346-4ed4-9a4e-674d90a35e74/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00145,"epssPercentile":0.03313,"ingestedAt":"2026-10-09T07:28:22.267Z","slug":"CVE-2026-92990","body":"## Overview\n\nThe SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218546,"id":"CVE-2026-92990","ts":1791561813555,"field":"cvss","old":null,"new":"5.3"},{"seq":218545,"id":"CVE-2026-92990","ts":1791561813555,"field":"severity","old":"none","new":"medium"}]}