Ghostwire

CVE-2026-14554: The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them...

HIGH CVSS 0.0

Published: July 31, 2026 | Last Modified: July 31, 2026

Description

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References