What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES smtp-amazon-ses allows SQL Injection.This issue affects SMTP for Amazon SES: from n/a through <= 1.9.
Explanation of Vulnerability in Simple Terms
02Summary
YayCommerce SMTP for Amazon SES versions 1.9 and earlier contain a SQL injection vulnerability in database query handling. An authenticated administrator can craft malicious input to execute arbitrary SQL commands, potentially reading or modifying site data. The vulnerability requires high-level privileges and does not affect data integrity directly, but can expose sensitive information and degrade availability.
What an attacker can do
03Attacker Capabilities
Read or delete database records by injecting SQL commands through the plugin interface.
Potential impact on your site
04Site Impact
A compromised admin account could expose customer data, email configurations, or disable the site's email functionality.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress/CMS installation.
Key dates
06Disclosure timeline
July 16, 2025
CVE published
May 13, 2026
Record updated