CVE-2026-3430
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
06/08/2026
Last modified:
06/08/2026
Description
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH



