PT-2026-42056 · Constantcontact · Creative Mail – Easier Wordpress & Woocommerce Email Marketing

·

CVE-2026-3985

·

Published

2026-05-20

·

Updated

2026-07-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Creative Mail – Easier WordPress & WooCommerce Email Marketing versions prior to 1.7.0
Description An unauthenticated attacker can perform a blind SQL injection, which is a technique used to extract data from a database by asking the server true or false questions. The issue occurs due to insufficient escaping of the user-supplied checkout uuid parameter and a lack of proper preparation of the SQL query within the has checkout consent() function. This allows the attacker to append additional SQL queries to extract sensitive information, such as administrator hashes and secret tokens. Full exploitation requires WooCommerce to be installed. Over 300,000 users are potentially affected.
Recommendations Update the plugin to a version newer than 1.6.9. As a temporary workaround, disable the plugin if WooCommerce is also installed.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3985

Affected Products

Creative Mail – Easier Wordpress & Woocommerce Email Marketing