HIGH
Creative Mail
CVE published 2026-08-06
CVE-2026-3430
The Creative Mail WordPress plugin, versions 1.6.5 to 1.6.9, is vulnerable to an unauthenticated SQL injection attack due to improper sanitization and escaping of a parameter used in an SQL statement. This vulnerability has a CVSS score of 8.6, indicating high severity. WordPress site administrators and users of the Creative Mail plugin should be aware of this vulnerability and take necessary actions to m [truncated]