CyberRota Analysis
AI-GeneratedThe Creative Mail plugin for WordPress versions 1.6.5 to 1.6.9 is vulnerable to unauthenticated SQL injection due to inadequate sanitization and escaping of parameters in SQL statements when managing abandoned cart emails. This flaw could allow attackers to manipulate the database, potentially leading to data exposure or corruption. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.