Executive brief
The Creative Mail plugin for WordPress, used for managing email marketing and WooCommerce customer communications, contains a security flaw that allows unauthorized individuals to access sensitive database information. By sending a specially crafted request, an attacker can bypass security controls to view private data stored in the website's database. This could lead to the exposure of customer details, order history, or other confidential site information.
Technical details
The Creative Mail plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient input validation and a lack of SQL query preparation in the `has_checkout_consent()` method. Specifically, the 'checkout_uuid' parameter is not properly escaped before being included in a database query. An attacker can exploit this by sending a crafted web request to append malicious SQL commands to existing queries. This vulnerability allows for the extraction of sensitive data from the WordPress database. The issue affects all versions of the plugin up to and including 1.6.9.
Affected products
- Constant Contact Creative Mail – Easier WordPress & WooCommerce Email Marketing Up to, and including, 1.6.9
Timeline
- 2026-05-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/creative-mail-by-constant-contact/tags/1.6.9/src/Managers/CheckoutManager.php
- https://plugins.trac.wordpress.org/browser/creative-mail-by-constant-contact/tags/1.6.9/src/Managers/DatabaseManager.php
- https://plugins.trac.wordpress.org/browser/creative-mail-by-constant-contact/trunk/src/Managers/DatabaseManager.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/39c17935-a853-407f-a99d-3828561919e6?source=cve