CVE-2026-3430
EUVD-2026-5408806.08.2026, 16:16
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.