← WordPress Vulnerabilities
WordPress security by component

Creative Mail

Creative Mail is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 8.5.

Plugin slug: creative-mail-by-constant-contact

CVE-2026-65547: Creative Mail through 1.6.9 permits Subscriber-level SQL injection

A logged-in user with Subscriber access can send crafted input that reaches a database query without safe parameterization in Creative Mail 1.6.9 and earlier. The CNA does not disclose the request action or endpoint, vulnerable parameter, query or function. The CVSS record indicates high confidentiality impact and low availability impact, so exploitation can expose database data and may disrupt the affected query path.

PublishedAug 06, 2026
Known safe version> 1.6.9
Published vulnerabilities for creative-mail-by-constant-contact
Safe version
Aug 06, 2026 CVE-2026-65547
Creative Mail through 1.6.9 permits Subscriber-level SQL injection
A logged-in user with Subscriber access can send crafted input that reaches a database query without safe parameterization in Creative Mail 1.6.9 and earlier. The CNA does not disclose the request action or endpoint, vulnerable parameter, query or function. The CVSS record indicates high confidentiality impact and low availability impact, so exploitation can expose database data and may disrupt the affected query path.
> 1.6.9
CVE8.5
NVDPending
May 20, 2026 CVE-2026-3985
Creative Mail – Easier WordPress & WooCommerce Email Marketing: SQL injection
Creative Mail – Easier WordPress & WooCommerce Email Marketing is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.6.9.
> 1.6.9
CVE7.5
NVDPending
Nov 18, 2022 CVE-2022-44740
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Nov 18, 2022 CVE-2022-40687
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Nov 18, 2022 CVE-2022-40686
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8