← WordPress Vulnerabilities
WordPress security by component

YayMail

YayMail is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 7.6.

Plugin slug: yaymail

CVE-2026-39498: YayMail: Code execution

YayMail is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 4.3.3.

PublishedJun 15, 2026
Known safe version4.3.4
Safe version
Jun 15, 2026 CVE-2026-39498
YayMail: Code execution
YayMail is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 4.3.3.
4.3.4
CVE7.2
NVDPending
Apr 08, 2026 CVE-2026-39496
YayMail: SQL injection
YayMail is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.3.3.
4.3.4
CVE7.6
NVDPending
Feb 19, 2026 CVE-2026-27327
YayMail: A security weakness
YayMail is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-1943
YayMail – WooCommerce Email Customizer: Cross-site scripting
YayMail – WooCommerce Email Customizer is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVDPending
Feb 18, 2026 CVE-2026-1938
YayMail – WooCommerce Email Customizer: A security weakness
YayMail – WooCommerce Email Customizer is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 18, 2026 CVE-2026-1831
YayMail - WooCommerce Email Customizer: A security weakness
YayMail - WooCommerce Email Customizer is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE2.7
NVDPending
Feb 18, 2026 CVE-2026-1937
YayMail – WooCommerce Email Customizer: Privilege escalation or authentication bypass
YayMail – WooCommerce Email Customizer is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.2
NVDPending