WordPress security by component
Creative Mail – Easier WordPress & WooCommerce Email Marketing
Plugin description
Creative Mail – Easier WordPress & WooCommerce Email Marketing is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 20, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
creative-mail-by-constant-contactLatest vulnerability
CVE-2026-3985: Creative Mail – Easier WordPress & WooCommerce Email Marketing: SQL injection
Creative Mail – Easier WordPress & WooCommerce Email Marketing is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.6.9.
| Safe version |
|
||
|---|---|---|---|
| May 20, 2026 |
CVE-2026-3985
Creative Mail – Easier WordPress & WooCommerce Email Marketing: SQL injection
Creative Mail – Easier WordPress & WooCommerce Email Marketing is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.6.9.
|
> 1.6.9 |
CVE7.5
NVDPending
|
| Nov 18, 2022 |
CVE-2022-44740
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-40687
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-40686
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|