Junglewise Threat Intelligence

CVE-2026-7618: EnvíaloSimple Email Marketing SQL injection in orderby parameter

CVE-2026-7618 · Severity: medium · CVSS 4.9 · Published 2026-05-27

Executive brief

The EnvíaloSimple plugin for WordPress, which is used for managing email marketing and newsletters, contains a security flaw that could allow an administrator to access sensitive information from the website's database. By sending specially crafted requests, an authorized user with high-level permissions can bypass standard security checks to run unauthorized database queries. This could lead to the exposure of confidential site data, though it requires the attacker to already have administrative access.

Technical details

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection due to insufficient escaping on the 'orderby' user-supplied parameter and a lack of sufficient preparation on existing SQL queries. The vulnerability exists in versions up to and including 2.4.5. An attacker with administrator-level privileges can exploit this via the network by appending malicious SQL statements to legitimate queries. Because the injection is time-based and blind, the attacker can infer data from the database based on the time it takes for the server to respond. This can be used to extract sensitive information such as user credentials or configuration details.

Affected products

  • EnvíaloSimple EnvíaloSimple: Email Marketing y Newsletters Up to, and including, 2.4.5

Timeline

  • 2026-05-27: disclosed: Vulnerability published by Wordfence and NVD

References