# CVE-2026-3985: Blind SQL Injection in Creative Mail WordPress Plugin, Discovered by Fully Automated AI Exploitation Pipeline

> An unauthenticated blind SQL injection (CVE-2026-3985, CVSS 7.5) in the 'checkout_uuid' handling of the Creative Mail for WordPress & WooCommerce Email Marketing plugin (300,000+ installs) allows an attacker to exfiltrate database contents, including administrator password hashes, via a time-based multi-request attack chain that requires WooCommerce to be installed alongside the plugin. The flaw is notable because it was discovered and weaponized end-to-end by Intruder's fully automated AI pipeline (Joern code slicing + Claude Sonnet triage + Claude Opus exploitability assessment + a Docker-sandboxed exploitation agent) with no human-written exploit code, and was independently reported by researcher Dmitrii Ignatyev of CleanTalk via the Wordfence Bug Bounty Program. The plugin has been pulled from the WordPress.org repository pending review.

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-07-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1376
- **ID:** TL-2026-1376
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3985

## Description

CVE-2026-3985 is an unauthenticated, time-based blind SQL injection in the Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin (WordPress.org slug creative-mail-by-constant-contact), affecting all versions up to and including 1.6.9. The vulnerable sink is the has_checkout_consent() method in the plugin's DatabaseManager.php, which builds a query as `$wpdb->prepare("SELECT checkout_consent FROM {$table_name} WHERE checkout_uuid = '{$checkout_uuid}'")` — the $checkout_uuid variable is concatenated directly into the SQL string rather than passed as a bound parameter to wpdb->prepare(), so the surrounding prepare() call provides no protection. The root cause was masked from the plugin author's own static analysis tooling: a `// phpcs:disable WordPress.DB.PreparedSQL` comment intended to silence a warning about the $table_name variable inadvertently suppressed analysis for the entire vulnerable line, hiding the missing-preparation bug from PHPCS/WPCS scans.

Exploitation is a multi-stage, chained-request attack rather than a single malicious HTTP request, which is why the authors argue it evades classic single-request SAST/DAST and WAF signature detection: (1) the attacker sends an initial request containing a GET parameter named ce4wp-recover populated with a SQL injection payload; (2) the plugin processes this parameter via `filter_input(INPUT_GET, 'ce4wp-recover', FILTER_SANITIZE_STRING, FILTER_FLAG_NO_ENCODE_QUOTES)` and stores the raw, unsanitized value into the current WooCommerce/WordPress session; (3) on a later request, the stored value is retrieved via `$uuid = WC()->session->get(self::CHECKOUT_UUID)` and passed into the vulnerable has_checkout_consent() method, where it is used unescaped inside the SQL WHERE clause; (4) the injected clause only executes if has_checkout_consent() is reached, which requires the site to have WooCommerce active alongside Creative Mail, tying successful exploitation to that specific plugin combination (WooCommerce itself has 7M+ active installs, so the combination is common on e-commerce sites). Because the endpoint returns no direct query output, exploitation relies on time-based blind techniques: the generated PoC injects a baseline SQL sleep of 4 seconds, but because the vulnerable query executes multiple times per logical request in the plugin's checkout-consent flow, the observed real-world delay per boolean test is roughly 35 seconds; the PoC implements a time-based binary/character search loop that reconstructs database content — including administrator password hashes and secret/authentication tokens — one bit or character at a time from response timing alone.

What distinguishes this disclosure is the discovery and exploit-generation process. Security firm Intruder built and ran a four-stage, fully automated AI vulnerability-research pipeline (internally described in their write-up as a "vulnerability vending machine"): Stage 1 uses the Joern static-analysis/code-property-graph engine with broadly scoped rules to flag interesting, potentially-unauthenticated entry points in WordPress plugin source (REST routes, template hooks, and AJAX actions). Stage 2 uses Joern to extract minimal "program slices" — the vulnerable function plus its full call chain — removing surrounding code noise, and applies lightweight taint tracking to discard obviously-safe sinks before any LLM sees the code. Stage 3 hands each candidate slice to Claude Sonnet as a cheap, high-throughput triage model whose only job is to discard code paths with no plausible security relevance. Stage 4 passes the surviving, higher-value candidates to Claude Opus for a deeper exploitability assessment; viable candidates are then handed to a dedicated exploitation agent that spins up the target software inside a Docker container and iteratively develops and tests a working proof-of-concept against the live container. For CVE-2026-3985, Intruder states the exploitation agent produced the final working PoC "straight out of the exploitation agent, no edits," i.e. with no human authoring or hand-tuning of the exploit code — the first time a fully agent-generated, human-unedited exploit for a real, previously-unknown vulnerability of this kind has been publicly documented by the firm. Intruder's write-up further states the pipeline has surfaced "many" additional vulnerabilities that remain under coordinated disclosure pending vendor patches, to be published later at security conferences.

CVE-2026-3985 was independently identified by external researcher Dmitrii Ignatyev of CleanTalk Inc. and reported through the Wordfence Bug Bounty / Responsible Disclosure Program on 27 April 2026; Wordfence notified the reporting parties of the duplicate finding (Intruder's automated pipeline had found the same bug independently) on 18 May 2026, and Wordfence publicly disclosed the vulnerability as CVE-2026-3985 on 19 May 2026 (Wordfence Intelligence lists the public disclosure date as 20 May 2026). Intruder published its own technical write-up and PoC on 11 June 2026. As of the most recent bulletins reviewed, no patched version of Creative Mail has been published, and the plugin has been pulled from the WordPress.org plugin directory pending review — leaving the estimated 300,000+ sites that had it installed unable to receive an official in-repo update and exposed if WooCommerce is also active. This case is a concrete illustration of a broader emerging trend: autonomous or semi-autonomous LLM agent pipelines are now capable of discovering novel vulnerabilities in widely deployed software and generating fully working exploit code without a human in the exploitation loop, compressing the time from code-scan to weaponized PoC and raising the bar for defenders who must now assume similarly-automated pipelines are available to less scrupulous actors as well as researchers.

## MITRE ATT&CK

- T1596 Search Open Technical Databases
- T1595.002 Vulnerability Scanning
- T1587.004 Exploits
- T1588.005 Exploits
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1555 Credentials from Password Stores
- T1552.001 Credentials In Files
- T1213 Data from Information Repositories
- T1119 Automated Collection
- T1041 Exfiltration Over C2 Channel
- T1531 Account Access Removal

## Sources

- [We built a vulnerability vending machine: AI tokens in, zero-days out](https://www.bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out/)
- [A 0-day vending machine: No Mythos necessary](https://www.intruder.io/research/a-0-day-vending-machine-no-mythos-necessary)
- [Creative Mail – Easier WordPress & WooCommerce Email Marketing Plugin Vulnerability (CVE-2026-3985)](https://freshysites.com/security-bulletins/creative-mail-easier-wordpress-woocommerce-email-marketing-plugin-vulnerability-cve-2026-3985/)
- [Fortify WordPress Against Emerging Threats (CVE-2026-3985)](https://managed-wp.com/blogs/fortify-wordpress-against-emerging-threats-cve20263985-2026-05-21)
- [Fortify WordPress Against Emerging Threats (CVE-2026-3985) - WP-Firewall](https://wp-firewall.com/fortify-wordpress-against-emerging-threats-published-on-2026-05-21-cve-2026-3985-2)
- [WordPress Vulnerability Database — Wordfence Intelligence](https://www.wordfence.com/threat-intel/vulnerabilities)
- [Vulnerabilities and security research for creative-mail-by-constant-contact](https://research.cleantalk.org/reports/app/creative-mail-by-constant-contact)
- [CVE Record: CVE-2026-3985](https://www.cve.org/CVERecord?id=CVE-2026-3985)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1376
