CVE-2026-59537

Sender · Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce

An SQL injection vulnerability in the Sender WordPress plugin allows authenticated administrators to execute arbitrary SQL commands via improper input neutralization.

Executive summary

An authenticated SQL injection vulnerability in the Sender WordPress plugin could allow an administrator to compromise database integrity or access sensitive information.

Vulnerability

This is an improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability requires high privileges (authenticated administrator) to exploit, allowing an attacker to manipulate backend database queries.

Business impact

Successful exploitation allows an attacker with administrative access to perform unauthorized database operations, potentially leading to data exfiltration or corruption. While the CVSS score of 7.6 reflects a high severity, the requirement for administrative privileges limits the attack surface to existing internal users or compromised accounts.

Remediation

Immediate Action: Update the Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin to version 2.10.23 or higher.

Proactive Monitoring: Review database query logs for anomalous or unauthorized syntax patterns that deviate from standard plugin operations.

Compensating Controls: Ensure that database service accounts operate with the principle of least privilege, restricting the ability of the plugin to execute administrative-level SQL commands.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations using the Sender marketing plugin should prioritize this update as part of their standard patch management cycle. Given that administrative access is required for exploitation, administrators should also audit user account activity to ensure no unauthorized accounts have been created or escalated.