CVE-2026-3430 UNKNOWN

CVE-2026-3430

Published: 2026-08-06

Description

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…