PT-2026-68617 · WordPress · Creative Mail

·

CVE-2026-3430

·

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Creative Mail versions 1.6.5 through 1.6.9
Description The Creative Mail WordPress plugin fails to sanitize and escape a parameter before incorporating it into an SQL statement. This flaw allows an unauthenticated user to perform an SQL injection when the abandoned cart email feature is managed by the plugin.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3430

Affected Products

Creative Mail