Known vulnerabilities in YayMail – WooCommerce Email Customizer
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
7Reported vulnerabilities
7.2Highest CVSS score
4.4.2Latest version
50,000+Active installs
What to do now
Update YayMail – WooCommerce Email Customizer to 4.3.4 or later.
7 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-1937 | High | 0.4% | 0 to 4.3.2 (inclusive) | 4.3.3 |
February 18, 2026 |
| CVE-2026-39498 | Medium | 0.4% | 4.3.3 and earlier | 4.3.4 |
April 20, 2026 |
| CVE-2026-1938 | Medium | 0.3% | 0 to 4.3.2 (inclusive) | 4.3.3 |
February 18, 2026 |
| CVE-2026-39496 | Medium | 0.3% | 4.3.3 and earlier | 4.3.4 |
March 15, 2026 |
| CVE-2026-1943 | Medium | 0.3% | 0 to 4.3.2 (inclusive) | 4.3.3 |
February 18, 2026 |
| CVE-2026-27327 | Medium | 0.2% | 4.3.2 and earlier | 4.3.3 |
January 6, 2026 |
| CVE-2026-1831 | Low | 0.3% | 0 to 4.3.2 (inclusive) | 4.3.3 |
February 18, 2026 |