Junglewise Threat Intelligence

CVE-2026-39496: YayCommerce YayMail Blind SQL Injection

CVE-2026-39496 · Severity: high · CVSS 7.6 · Published 2026-04-08

Executive brief

YayMail is a WordPress plugin used to customize WooCommerce email templates. A security vulnerability in this plugin could allow an attacker with high-level administrative access to interact directly with the website's database. This could lead to the theft of sensitive information or unauthorized access to customer data.

Technical details

A Blind SQL Injection vulnerability exists in the YayCommerce YayMail plugin for WordPress due to improper neutralization of special elements used in an SQL command. The flaw is present in versions up to and including 4.3.3. An attacker with 'Shop Manager' or higher privileges can exploit this vulnerability via network requests to execute arbitrary SQL queries. This could allow for the exfiltration of sensitive data from the WordPress database. The issue was addressed in version 4.3.4.

Affected products

  • YayCommerce YayMail <= 4.3.3

Timeline

  • 2026-02-13: disclosed: Reported by Nguyen Ba Khanh via Patchstack
  • 2026-03-15: advisory: Patchstack published advisory
  • 2026-04-08: advisory: NVD published CVE-2026-39496
  • 2026-04-08: patched: Patch available in version 4.3.4

References

Related threats