PT-2026-22334 · WordPress · Mailarchiver

Ronnachai Chaipha

·

Published

2026-02-27

·

Updated

2026-02-27

·

CVE-2026-2831

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MailArchiver plugin for WordPress versions prior to 4.5.1
Description The MailArchiver plugin for WordPress is susceptible to SQL Injection due to insufficient input validation and query preparation. Specifically, the logid parameter is not adequately sanitized, allowing authenticated attackers with Administrator-level access or higher to inject additional SQL queries into existing database queries. This can lead to the extraction of sensitive information from the database.
Recommendations Update the MailArchiver plugin to version 4.5.1 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-2831

Affected Products

Mailarchiver