Sceawere

Vulnerability Detail

CVE-2026-39795UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated SQL Injection in SendPress

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
16h ago
Vendor
brewlabs
Product
SendPress Newsletters
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-10-06T09:17:52.540Z",
  "pubdate": "2026-10-06T09:17:52.540Z",
  "executiveSummary": "The SendPress Newsletters plugin for WordPress, in versions 1.26.1.20 and prior, contains a critical unauthenticated SQL injection vulnerability.\nThe vulnerability resides in the application's handling of user-supplied input, which is inadequately sanitized before being processed in database queries.\nSuccessful exploitation allows an unauthenticated, remote attacker to execute arbitrary SQL commands, potentially leading to unauthorized data exfiltration, modification, or deletion within the underlying WordPress database.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the entire WordPress installation.\nExploitation does not require authentication or elevated administrative privileges, lowering the barrier for entry for malicious actors.\nThe vulnerability is accessible via the network, allowing external exploitation if the application is reachable.\nUsers are advised to identify if they are running an affected version and implement the recommended mitigations immediately.",
  "technicalDetails": "The vulnerability is identified as a classic SQL Injection (SQLi) flaw within the SendPress Newsletters plugin architecture, specifically occurring due to insufficient input validation and improper sanitization of parameters supplied to database-interacting functions.\nIn the affected versions (<= 1.26.1.20), specific entry points within the plugin fail to use prepared statements or robust parameter binding when constructing dynamic SQL queries. Instead, user-controlled input is directly concatenated into the SQL command strings executed against the WordPress database via the $wpdb class.\nThe attack flow begins when an unauthenticated attacker sends a crafted HTTP request to a vulnerable endpoint within the plugin. The attacker injects malicious SQL syntax into a parameter expected by the application. Because this input is not properly escaped, the database management system interprets the malicious input as part of the intended query structure rather than as data.\nThe root cause is the reliance on insecure query construction patterns in the affected versions. An attacker can manipulate the query logic to bypass authentication, extract sensitive information from the wp_users table, read plugin-specific configuration data, or potentially modify database records.\nPost-exploitation, an attacker could achieve complete database compromise. This includes but is not limited to: dumping the contents of the database, altering user account privileges to escalate their own access level within the WordPress dashboard, or corrupting plugin functionality.\nThe vulnerability is exposed over the network, meaning that any publicly accessible WordPress installation utilizing the vulnerable SendPress plugin version is susceptible to this remote attack vector. The absence of authentication requirements means the vulnerability can be leveraged by any actor capable of navigating to the specific vulnerable URL path and submitting the malicious payload.\nTechnically, the vulnerability exists because the plugin fails to enforce input validation policies consistent with WordPress security best practices, such as utilizing the $wpdb->prepare() function, which is designed to prevent SQL injection by separating the query structure from the data parameters."
}
CVE-2026-39795: Unauthenticated SQL Injection in SendPress (CRITICAL Severity, CVSS: 9.3) | Sceawere