CVE-2026-3430: Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
Published Aug 6, 2026
·Updated
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
Affected Software
1 affected component
Creative Mail WordPress plugin>=1.6.5<=1.6.9
Event History
Aug 6, 2026
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-3430?
CVE-2026-3430 is rated as high severity with a score of 8.6.
2
How do I fix CVE-2026-3430?
To fix CVE-2026-3430, update the Creative Mail WordPress plugin to version 1.6.10 or later.
3
What type of vulnerability is CVE-2026-3430?
CVE-2026-3430 is an unauthenticated SQL injection vulnerability.
4
Which versions of Creative Mail are affected by CVE-2026-3430?
CVE-2026-3430 affects Creative Mail WordPress plugin versions 1.6.5 to 1.6.9.
5
How does CVE-2026-3430 impact my website?
CVE-2026-3430 could allow attackers to execute arbitrary SQL queries, potentially exposing sensitive data.