Junglewise Threat Intelligence

CVE-2026-39498: YayCommerce YayMail PHP Object Injection in Shop Manager

CVE-2026-39498 · Severity: high · CVSS 7.2 · Published 2026-06-15

Executive brief

YayMail is a popular WordPress plugin used to customize WooCommerce email templates. A security flaw allows users with 'Shop Manager' privileges to inject malicious code into the website's server. If exploited, this could lead to full site takeover, data theft, or the deletion of website files, depending on other software installed on the site.

Technical details

The YayMail plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 4.3.3. This issue stems from the deserialization of untrusted data (CWE-502) provided by a user with Shop Manager or higher privileges. An attacker can exploit this by submitting a specially crafted payload that, if a suitable POP chain is present on the server, could lead to remote code execution, SQL injection, or arbitrary file deletion. The vulnerability is addressed in version 4.3.4.

Affected products

  • YayCommerce YayMail <= 4.3.3

Timeline

  • 2026-02-26: other: Reported by researcher daroo
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats