Creative Mail
by WordPress
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-3430 | Hig | 0.56 | 8.6 | 0.00 | Aug 6, 2026 | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | ||
| CVE-2026-65547 | Hig | 0.55 | 8.5 | 0.00 | Aug 6, 2026 | Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | ||
| CVE-2026-3985 | Hig | 0.49 | 7.5 | 0.00 | May 20, 2026 | The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of… | ||
| CVE-2022-44740 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress. | ||
| CVE-2022-40687 | Med | 0.35 | 5.4 | 0.01 | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. | ||
| CVE-2022-40686 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. |
- risk 0.56cvss 8.6epss 0.00
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
- risk 0.49cvss 7.5epss 0.00
The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of…
- risk 0.35cvss 5.4epss 0.00
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.
- risk 0.35cvss 5.4epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.