CVE-2026-3430 - Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
CVE ID :CVE-2026-3430
Published : Aug. 6, 2026, 4:16 p.m. | 3 hours, 10 minutes ago
Description :The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 6, 2026, 4:16 p.m. | 3 hours, 10 minutes ago
Description :The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...