Threat reportVulnerabilityTL-2026-1376
CVE-2026-3985: Blind SQL Injection in Creative Mail WordPress Plugin, Discovered by Fully Automated AI Exploitation Pipeline
CVE-2026-3985 (TL-2026-1376), also tracked as Creative Mail checkout_uuid SQL Injection, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-07-15. It has no confirmed attribution, affects Constant Contact / Creative Mail Creative Mail – Easier WordPress &, references 1 CVE (CVE-2026-3985), maps to 15 MITRE ATT&CK techniques (T1027, T1041, T1082), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-1376
- Threat ID
- TL-2026-1376
- Also known as
- Creative Mail checkout_uuid SQL Injection, Vulnerability Vending Machine CVE-2026-3985
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- ecommerce, retail, small business smb web presence, marketing email services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in CVE-2026-3985
Malware and tooling: Claude Opus, Claude Sonnet, Joern
How CVE-2026-3985 works
An unauthenticated blind SQL injection (CVE-2026-3985, CVSS 7.5) in the 'checkout_uuid' handling of the Creative Mail for WordPress & WooCommerce Email Marketing plugin (300,000+ installs) allows an attacker to exfiltrate database contents, including administrator password hashes, via a time-based multi-request attack chain that requires WooCommerce to be installed alongside the plugin. The flaw is notable because it was discovered and weaponized end-to-end by Intruder's fully automated AI pipeline (Joern code slicing + Claude Sonnet triage + Claude Opus exploitability assessment + a Docker-sandboxed exploitation agent) with no human-written exploit code, and was independently reported by researcher Dmitrii Ignatyev of CleanTalk via the Wordfence Bug Bounty Program. The plugin has been pulled from the WordPress.org repository pending review.
CVE-2026-3985 is an unauthenticated, time-based blind SQL injection in the Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin (WordPress.org slug creative-mail-by-constant-contact), affecting all versions up to and including 1.6.9. The vulnerable sink is the has_checkout_consent() method in the plugin's DatabaseManager.php, which builds a query as `$wpdb->prepare("SELECT checkout_consent FROM {$table_name} WHERE checkout_uuid = '{$checkout_uuid}'")` — the $checkout_uuid variable is concatenated directly into the SQL string rather than passed as a bound parameter to wpdb->prepare(), so the surrounding prepare() call provides no protection. The root cause was masked from the plugin author's own static analysis tooling: a `// phpcs:disable WordPress.DB.PreparedSQL` comment intended to silence a warning about the $table_name variable inadvertently suppressed analysis for the entire vulnerable line, hiding the missing-preparation bug from PHPCS/WPCS scans.
Exploitation is a multi-stage, chained-request attack rather than a single malicious HTTP request, which is why the authors argue it evades classic single-request SAST/DAST and WAF signature detection: (1) the attacker sends an initial request containing a GET parameter named ce4wp-recover populated with a SQL injection payload; (2) the plugin processes this parameter via `filter_input(INPUT_GET, 'ce4wp-recover', FILTER_SANITIZE_STRING, FILTER_FLAG_NO_ENCODE_QUOTES)` and stores the raw, unsanitized value into the current WooCommerce/WordPress session; (3) on a later request, the stored value is retrieved via `$uuid = WC()->session->get(self::CHECKOUT_UUID)` and passed into the vulnerable has_checkout_consent() method, where it is used unescaped inside the SQL WHERE clause; (4) the injected clause only executes if has_checkout_consent() is reached, which requires the site to have WooCommerce active alongside Creative Mail, tying successful exploitation to that specific plugin combination (WooCommerce itself has 7M+ active installs, so the combination is common on e-commerce sites). Because the endpoint returns no direct query output, exploitation relies on time-based blind techniques: the generated PoC injects a baseline SQL sleep of 4 seconds, but because the vulnerable query executes multiple times per logical request in the plugin's checkout-consent flow, the observed real-world delay per boolean test is roughly 35 seconds; the PoC implements a time-based binary/character search loop that reconstructs database content — including administrator password hashes and secret/authentication tokens — one bit or character at a time from response timing alone.
What distinguishes this disclosure is the discovery and exploit-generation process. Security firm Intruder built and ran a four-stage, fully automated AI vulnerability-research pipeline (internally described in their write-up as a "vulnerability vending machine"): Stage 1 uses the Joern static-analysis/code-property-graph engine with broadly scoped rules to flag interesting, potentially-unauthenticated entry points in WordPress plugin source (REST routes, template hooks, and AJAX actions). Stage 2 uses Joern to extract minimal "program slices" — the vulnerable function plus its full call chain — removing surrounding code noise, and applies lightweight taint tracking to discard obviously-safe sinks before any LLM sees the code. Stage 3 hands each candidate slice to Claude Sonnet as a cheap, high-throughput triage model whose only job is to discard code paths with no plausible security relevance. Stage 4 passes the surviving, higher-value candidates to Claude Opus for a deeper exploitability assessment; viable candidates are then handed to a dedicated exploitation agent that spins up the target software inside a Docker container and iteratively develops and tests a working proof-of-concept against the live container. For CVE-2026-3985, Intruder states the exploitation agent produced the final working PoC "straight out of the exploitation agent, no edits," i.e. with no human authoring or hand-tuning of the exploit code — the first time a fully agent-generated, human-unedited exploit for a real, previously-unknown vulnerability of this kind has been publicly documented by the firm. Intruder's write-up further states the pipeline has surfaced "many" additional vulnerabilities that remain under coordinated disclosure pending vendor patches, to be published later at security conferences.
CVE-2026-3985 was independently identified by external researcher Dmitrii Ignatyev of CleanTalk Inc. and reported through the Wordfence Bug Bounty / Responsible Disclosure Program on 27 April 2026; Wordfence notified the reporting parties of the duplicate finding (Intruder's automated pipeline had found the same bug independently) on 18 May 2026, and Wordfence publicly disclosed the vulnerability as CVE-2026-3985 on 19 May 2026 (Wordfence Intelligence lists the public disclosure date as 20 May 2026). Intruder published its own technical write-up and PoC on 11 June 2026. As of the most recent bulletins reviewed, no patched version of Creative Mail has been published, and the plugin has been pulled from the WordPress.org plugin directory pending review — leaving the estimated 300,000+ sites that had it installed unable to receive an official in-repo update and exposed if WooCommerce is also active. This case is a concrete illustration of a broader emerging trend: autonomous or semi-autonomous LLM agent pipelines are now capable of discovering novel vulnerabilities in widely deployed software and generating fully working exploit code without a human in the exploitation loop, compressing the time from code-scan to weaponized PoC and raising the bar for defenders who must now assume similarly-automated pipelines are available to less scrupulous actors as well as researchers.
MITRE ATT&CK techniques used in TL-2026-1376
Defense Evasion
T1027 Obfuscated Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1082 System Information Discovery
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Impact
Credential Access
T1552.001 Credentials In Files; T1555 Credentials from Password Stores
Resource Development
T1587.004 Exploits; T1588.005 Exploits
Reconnaissance
T1595.002 Vulnerability Scanning; T1596 Search Open Technical Databases
defense-impairment
Affected products and versions in CVE-2026-3985
- Constant Contact / Creative Mail — Creative Mail – Easier WordPress & WooCommerce Email Marketing (creative-mail-by-constant-contact)
Vulnerable versions: <= 1.6.9 - Automattic — WooCommerce (required companion plugin for exploitation path)
Vulnerable versions: any version enabling checkout session support alongside Creative Mail <= 1.6.9
Remediation for CVE-2026-3985
Patches
- No official patched version has been published as of the most recent bulletins reviewed; the plugin has instead been removed from the WordPress.org repository pending vendor review
Immediate actions
- Deactivate and remove the Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin (creative-mail-by-constant-contact) on any site where it is installed, since it has been pulled from the WordPress.org repository pending review and no patched version is currently distributed
- If the plugin cannot be removed immediately, deactivate WooCommerce on the same site or otherwise block reachability between the two plugins to prevent has_checkout_consent() from ever executing
- Deploy a WAF rule blocking requests containing SQL metacharacters or time-based SQLi patterns (SLEEP, BENCHMARK, WAITFOR DELAY) in the ce4wp-recover GET parameter
- Monitor WordPress/WooCommerce access logs for abnormal response-time patterns (repeated requests with multi-second response delays) on checkout-related endpoints, which indicate active time-based blind SQLi probing
- Rotate WordPress administrator password hashes and any secret/authentication tokens stored in the database if compromise is suspected, since successful exploitation directly targets these values
Workarounds
- Uninstall the Creative Mail plugin, or ensure WooCommerce is not simultaneously active on any site running Creative Mail up to and including version 1.6.9
- Apply virtual patching via a WordPress-aware WAF (e.g. Wordfence) blocking SQLi patterns in the ce4wp-recover parameter and checkout-consent related requests
Longer-term hardening
- Adopt static-analysis coverage review that checks for suppression comments (e.g. phpcs:disable) accidentally silencing entire lines rather than the single flagged issue, since this exact class of gap hid CVE-2026-3985 from the vendor's own tooling
- Require parameterized queries (bound $wpdb->prepare() placeholders) for all SQL built from user- or session-derived input across WordPress plugin codebases, with CI gating on raw string interpolation into SQL
- Track this incident as an indicator that adversaries and researchers alike now have access to automated AI vulnerability-discovery and exploit-generation pipelines (Joern + LLM triage/exploitability + exploitation agent); factor this into patch-latency risk models and prioritize faster review of plugins pulled from marketplaces pending security review
- Establish monitoring for multi-request, session-state-based attack chains (payload stored in one request, triggered in a later request) which are specifically designed to evade single-request WAF/IDS signatures
CVEs associated with CVE-2026-3985
CVE-2026-3985
Weaknesses (CWE) in CVE-2026-3985
Timeline of CVE-2026-3985
- CleanTalk's vulnerability database records three earlier CSRF vulnerabilities in the same Creative Mail plugin (CVE-2022-40687, CVE-2022-40686, CVE-2022-44740), establishing a prior history of security issues in the plugin's codebase predating CVE-2026-3985.
- Researcher Dmitrii Ignatyev of CleanTalk Inc. reports the checkout_uuid SQL injection in Creative Mail to the Wordfence Bug Bounty / Responsible Disclosure Program.
- Wordfence notifies the reporting researchers that the finding is a duplicate — Intruder's automated AI pipeline had independently discovered the same vulnerability via its Joern + Claude Sonnet + Claude Opus + exploitation-agent workflow.
- Wordfence publicly discloses the vulnerability and it is assigned CVE-2026-3985.
- Wordfence Intelligence and third-party security bulletins (FreshySites, Managed-WP, WP-Firewall) publish CVSS 7.5 / CWE-89 advisories describing the vulnerable checkout_uuid parameter and has_checkout_consent() method.
- Creative Mail – Easier WordPress & WooCommerce Email Marketing is pulled from the WordPress.org plugin repository pending security review, leaving no in-repo update path for the 300,000+ sites that had it installed.
- Intruder publishes its technical research write-up "A 0-day vending machine: No Mythos necessary," including the working, unedited time-based blind SQLi proof-of-concept generated entirely by its exploitation agent.
- BleepingComputer covers the disclosure in "We built a vulnerability vending machine: AI tokens in, zero-days out," bringing broader attention to the fully automated AI vulnerability-discovery and exploit-generation pipeline.
Sources cited for CVE-2026-3985
- We built a vulnerability vending machine: AI tokens in, zero-days out
- A 0-day vending machine: No Mythos necessary
- Creative Mail – Easier WordPress & WooCommerce Email Marketing Plugin Vulnerability (CVE-2026-3985)
- Fortify WordPress Against Emerging Threats (CVE-2026-3985)
- Fortify WordPress Against Emerging Threats (CVE-2026-3985) - WP-Firewall
- WordPress Vulnerability Database — Wordfence Intelligence
- Vulnerabilities and security research for creative-mail-by-constant-contact
- CVE Record: CVE-2026-3985
Detection coverage for TL-2026-1376
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1376 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.