CVE-2017-6098: Mail-Masta Project Mail-Masta

High severity, CVSS 7.2. EPSS: 5.2% chance of exploitation in the next 30 days.

A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.

Affected products

Published 2017-02-21. Last modified 2026-06-17.