PT-2026-64932 · WordPress · Sender – Newsletter

CVE-2026-59537

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce versions prior to 2.10.23
Description An SQL Injection issue exists that allows an administrator to execute malicious SQL queries. SQL Injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing unauthorized access to or manipulation of the database.
Recommendations Update Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce to version 2.10.23 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59537

Affected Products

Sender – Newsletter