The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Thu, 06 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | |
| Title | Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-06T15:09:23.403Z
Updated: 2026-08-06T15:47:36.619Z
Reserved: 2026-03-02T10:13:41.406Z
Link: CVE-2026-3430
Updated: 2026-08-06T15:47:33.508Z
Status : Received
Published: 2026-08-06T16:16:42.760
Modified: 2026-08-06T22:17:04.190
Link: CVE-2026-3430
No data.