CVE-2026-14554

MEDIUM

Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters

Title source: cna
STIX 2.1

Description

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/7b39bae3-41a2-4862-b7c3-1a386273d600/

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
None/Check & Log Email < 2.0.15
Published Jul 31, 2026
Tracked Since Jul 31, 2026