CyberRota Analysis
AI-GeneratedSendPress Newsletters versions up to 1.26.1.20 are vulnerable to an unauthenticated SQL injection, allowing attackers to execute arbitrary SQL queries on the database. This critical vulnerability could lead to data exposure or manipulation, making it imperative for users of affected versions to prioritize immediate updates or mitigations. Organizations utilizing this plugin should take action to safeguard their systems against potential exploitation.
CVE
CVE-2026-39795
Severity
CRITICAL
CVSS
9.3
EPSS
N/A
Original NVD Description
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.