Junglewise Threat Intelligence

CVE-2026-3985: Constant Contact Creative Mail SQL injection in has_checkout_consent

CVE-2026-3985 · Severity: high · CVSS 7.5 · Published 2026-05-20

Executive brief

The Creative Mail plugin for WordPress, used for managing email marketing and WooCommerce customer communications, contains a security flaw that allows unauthorized individuals to access sensitive database information. By sending a specially crafted request, an attacker can bypass security controls to view private data stored in the website's database. This could lead to the exposure of customer details, order history, or other confidential site information.

Technical details

The Creative Mail plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient input validation and a lack of SQL query preparation in the `has_checkout_consent()` method. Specifically, the 'checkout_uuid' parameter is not properly escaped before being included in a database query. An attacker can exploit this by sending a crafted web request to append malicious SQL commands to existing queries. This vulnerability allows for the extraction of sensitive data from the WordPress database. The issue affects all versions of the plugin up to and including 1.6.9.

Affected products

  • Constant Contact Creative Mail – Easier WordPress & WooCommerce Email Marketing Up to, and including, 1.6.9

Timeline

  • 2026-05-20: advisory: NVD publication date

References

Related threats