AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-3430

HIGH · CVSS 8.6 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Creative Mail plugin for WordPress versions 1.6.5 to 1.6.9 is vulnerable to unauthenticated SQL injection due to inadequate sanitization and escaping of parameters in SQL statements when managing abandoned cart emails. This flaw could allow attackers to manipulate the database, potentially leading to data exposure or corruption. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-3430
Severity
HIGH
CVSS
8.6
EPSS
0.24%
WordPress

Original NVD Description

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.