External risk intelligence

SendPress Newsletters SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-39795

The vulnerability affects a newsletter plugin for web content management systems. Such plugins are designed to interact with public-facing web traffic, often processing external requests to manage subscriptions or newsletters, making them commonly reachable from the internet in typical deployments.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves an unauthenticated SQL injection in a newsletter plugin for web content management systems, potentially exposing sensitive data. The technology affected is a plugin that handles user interactions for newsletters. The main concern is confirming relevance and exposure within our environment.

  • SQL injection in a newsletter tool.
  • Unauthenticated access to sensitive data.
  • Confirm relevance and exposure of the plugin.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to a website using the affected newsletter plugin. Since no authentication is required, an unauthenticated attacker can directly target the plugin's features. This could allow them to inject malicious SQL code, potentially leading to unauthorized data access or manipulation.

  • No authentication required.
  • SQL injection in newsletter features.
  • Unauthorized data access risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to inject SQL commands into the newsletter plugin. When supported by the advisory, this could lead to unauthorized access to or modification of the underlying database, potentially affecting WordPress site content and user data.

  • Database contents could be exposed.
  • SQL injection via network requests.
  • May impact site integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated SQL injection vulnerability in SendPress Newsletters requires immediate attention from teams managing WordPress sites. The first practical step is to identify all instances of the affected plugin, determine their internet reachability and business criticality, and then locate the accountable owner for remediation.

  • Identify affected plugin instances.
  • Verify internet exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the SendPress Newsletters plugin?

SendPress Newsletters is a WordPress plugin used to create, manage, and send email newsletters directly from a website's dashboard. It handles subscriber lists, email templates, and reporting, functioning as a bridge between your web server and your audience. Because it is designed to manage interactions like email sign-ups, it naturally handles data inputs from users visiting your site.

What does SQL injection mean for CVE-2026-39795?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain terms, the plugin fails to properly filter the data it receives before using it to query the database. This allows an attacker to manipulate the underlying database commands, potentially tricking the system into revealing sensitive information that should remain private.

How does an attacker trigger this vulnerability?

An attacker exploits this by sending specially crafted web requests to the plugin. Because the vulnerability is unauthenticated, the attacker does not need a login or valid account on your site to initiate the attack. However, the flaw requires the plugin to process these specific malicious inputs; standard, legitimate interactions with the newsletter subscription forms or settings will not trigger the bug.

Is my site at risk if it uses SendPress Newsletters?

Halo Surface Signal indicates that because this plugin is designed to process public-facing traffic for newsletter management, it is often reachable from the internet. If your WordPress site is publicly accessible, the plugin is likely exposed to these network-based requests. You should prioritize checking if your deployment is internet-facing, as this significantly increases the reachability of the vulnerability.

What should I do if I am running this plugin?

Your first step is to catalog every instance of the SendPress Newsletters plugin across your environment. Once identified, determine which instances are internet-facing and assess their business criticality. Coordinate with the relevant site owners to monitor for official updates or vendor guidance to remediate the vulnerability and protect your database content.

References