VYPR

Creative Mail

by WordPress

CVEs (6)

  • CVE-2026-3430HigAug 6, 2026
    risk 0.56cvss 8.6epss 0.00

    The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

  • CVE-2026-65547HigAug 6, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.

  • CVE-2026-3985HigMay 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2022-44740MedNov 18, 2022
    risk 0.35cvss 5.4epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.

  • CVE-2022-40687MedNov 18, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

  • CVE-2022-40686MedNov 18, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.