CVE-2026-3985 | constantcontact Creative Mail Plugin up to 1.6.9 on WordPress has_checkout_consent checkout_uuid sql injection (CNNVD-202605-4471)
A vulnerability described as critical has been identified in constantcontact Creative Mail Plugin up to 1.6.9 on WordPress. This affects the function has_checkout_consent. Executing a manipulation of the argument checkout_uuid can lead to sql injection.
This vulnerability appears as CVE-2026-3985. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.