VYPR

Yaymail

by WordPress

Source repositories

CVEs (6)

  • CVE-2026-39496HigApr 8, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through <= 4.3.3.

  • CVE-2026-39498HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.00

    Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

  • CVE-2026-1937HigFeb 18, 2026
    risk 0.47cvss 7.2epss 0.00

    The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2.…

  • CVE-2026-1943MedFeb 18, 2026
    risk 0.29cvss 4.4epss 0.00

    The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 4.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

  • CVE-2026-27327MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in YayCommerce YayMail yaymail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayMail: from n/a through <= 4.3.2.

  • CVE-2026-1938MedFeb 18, 2026
    risk 0.27cvss 5.3epss 0.00

    The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due to a missing authorization check on the `/yaymail-license/v1/license/delete` REST endpoint in versions up to, and including, 4.3.2. This makes it possible for…