CVE-2026-3430 PUBLISHED

Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi

Assigner: WPScan
Reserved: 02.03.2026 Published: 06.08.2026 Updated: 06.08.2026

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 8.6

Product Status

Vendor Unknown
Product Creative Mail
Versions Default: unknown
  • affected from 1.6.5 to 1.6.9 (incl.)

Credits

  • wcraft finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE