Impact
The vulnerability resides in the Creative Mail plugin for WordPress versions 1.6.9 and earlier. It allows an attacker exploiting untrusted input in subscriber handling code to inject arbitrary SQL statements into the database. This could lead to unauthorized data access, modification, or deletion, thereby compromising the confidentiality, integrity, or availability of subscriber information.
Affected Systems
This issue affects installations of the Constant Contact Creative Mail WordPress plugin, specifically version 1.6.9 and older. Sites utilizing these plugin releases are subject to the vulnerability and should be catalogued for remediation.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, so the current data does not indicate the exploit frequency. The vulnerability is not listed in the CISA KEV catalog, but given its nature and the known exploitation potential of SQL injection, it remains a significant risk. Attackers can trigger the flaw remotely via specially crafted HTTP requests that target the subscriber data API. The associated CWE-89 highlights the flaw's lack of proper input validation or parameterization.
OpenCVE Enrichment