All 3 CVE vulnerabilities found in YayMail, with AI-generated Chinese analysis, references, and POCs.
Vendor: YayCommerce
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-39498 | WordPress YayMail plugin <= 4.3.3 - PHP Object Injection vulnerability CWE-502 | 7.2 | High | 2026-06-15 |
| CVE-2026-39496 | WordPress YayMail plugin <= 4.3.3 - SQL Injection vulnerability CWE-89 | 7.6 | High | 2026-04-08 |
| CVE-2026-27327 | WordPress YayMail – WooCommerce Email Customizer plugin <= 4.3.2 - Broken Access Control vulnerability CWE-862 | 4.3 | Medium | 2026-02-19 |
All 3 known CVE vulnerabilities affecting YayMail with full Chinese analysis, references, and POCs where available.