plugin

Creative Mail By Constant Contact Vulnerabilities

9 known security issues reported for the Creative Mail By Constant Contact WordPress plugin. Most recent disclosed Jul 28, 2026.

5 high 1 medium

Running Creative Mail By Constant Contact on your site? Check whether your installed version is affected.

Scan your site free

Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Authenticated (Subscriber+) SQL Injection

medium

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...

CVSS:
6.5
Affected:
up to 1.6.9
Fix:
No patched version reported
Disclosed:
Jul 28, 2026

CVE-2026-65547 on NVD →

Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter

high

The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

CVSS:
7.5
Affected:
up to 1.6.9
Fix:
No patched version reported
Disclosed:
May 19, 2026

CVE-2026-3985 on NVD →

Creative Mail <= 1.6.9 - Unauthenticated SQL Injection

high

The Creative Mail plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries in...

CVSS:
7.5
Affected:
up to 1.6.9
Fix:
No patched version reported
Disclosed:
May 19, 2026

CVE-2026-3430 on NVD →

Creative Mail – Easier WordPress &amp; WooCommerce Email Marketing [creative-mail-by-constant-contact] < 1.6.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Nov 18, 2022

CVE-2022-40686 on NVD →

Creative Mail – Easier WordPress &amp; WooCommerce Email Marketing [creative-mail-by-constant-contact] < 1.6.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Nov 18, 2022

CVE-2022-40687 on NVD →

Creative Mail – Easier WordPress &amp; WooCommerce Email Marketing [creative-mail-by-constant-contact] < 1.6.0

unknown

[en] Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Nov 18, 2022

CVE-2022-44740 on NVD →

Creative Mail <= 1.5.4 - Cross-Site Request Forgery to Plugin Deactivation

high

The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on settings change. This makes it possible for unauthenticated attackers to deactivate arbitrary plugins via forged request granted they can tr...

CVSS:
8.8
Affected:
up to 1.5.4
Fixed in:
1.6.0
Disclosed:
Oct 28, 2022

CVE-2022-40686 on NVD →

Creative Mail <= 1.5.4 - Cross-Site Request Forgery

high

The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to perform actions such as resetting the plugin, toggling contact sy...

CVSS:
8.8
Affected:
up to 1.5.4
Fixed in:
1.6.0
Disclosed:
Oct 28, 2022

CVE-2022-44740 on NVD →

Creative Mail <= 1.5.4 - Cross-Site Request Forgery to Settings Disconnect

high

The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.4. This is due to missing or incorrect nonce validation on settings change. This makes it possible for unauthenticated attackers to reset the plugin's settings via forged request granted they can tri...

CVSS:
8.8
Affected:
up to 1.5.4
Fixed in:
1.6.0
Disclosed:
Oct 28, 2022

CVE-2022-40687 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database