WordPress security by component
Creative Mail
Plugin description
Creative Mail is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 8.5.
Plugin slug:
creative-mail-by-constant-contactLatest vulnerability
CVE-2026-65547: Creative Mail through 1.6.9 permits Subscriber-level SQL injection
A logged-in user with Subscriber access can send crafted input that reaches a database query without safe parameterization in Creative Mail 1.6.9 and earlier. The CNA does not disclose the request action or endpoint, vulnerable parameter, query or function. The CVSS record indicates high confidentiality impact and low availability impact, so exploitation can expose database data and may disrupt the affected query path.
| Safe version |
|
||
|---|---|---|---|
| Aug 06, 2026 |
CVE-2026-65547
Creative Mail through 1.6.9 permits Subscriber-level SQL injection
A logged-in user with Subscriber access can send crafted input that reaches a database query without safe parameterization in Creative Mail 1.6.9 and earlier. The CNA does not disclose the request action or endpoint, vulnerable parameter, query or function. The CVSS record indicates high confidentiality impact and low availability impact, so exploitation can expose database data and may disrupt the affected query path.
|
> 1.6.9 |
CVE8.5
NVDPending
|
| May 20, 2026 |
CVE-2026-3985
Creative Mail – Easier WordPress & WooCommerce Email Marketing: SQL injection
Creative Mail – Easier WordPress & WooCommerce Email Marketing is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.6.9.
|
> 1.6.9 |
CVE7.5
NVDPending
|
| Nov 18, 2022 |
CVE-2022-44740
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-40687
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-40686
Creative Mail By Constant Contact: Cross-site request forgery
Creative Mail By Constant Contact is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|