The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.CreditswcraftWPScanReferenceshttps://wpscan.com/vulnerability/eb2f34bd-c626-4831-a886-c82882073bcd/