CVE-2026-1937

HIGH EXPLOITED

YayMail WooCommerce Email Customizer <=4.3.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-1937 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Nxploited.

AI-analyzed exploit summary This repository contains a functional Proof-of-Concept (PoC) exploit for CVE-2026-1937, targeting the YayMail WooCommerce plugin. The exploit chain involves registering a user, logging in, extracting a nonce, and leveraging the `yaymail_import_state` AJAX action to escalate privileges by modifying WordPress options.

Description

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

Exploits (1)

nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2026-1937

This repository contains a functional Proof-of-Concept (PoC) exploit for CVE-2026-1937, targeting the YayMail WooCommerce plugin. The exploit chain involves registering a user, logging in, extracting a nonce, and leveraging the `yaymail_import_state` AJAX action to escalate privileges by modifying WordPress options.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: YayMail – WooCommerce Email Customizer Plugin for WordPress (versions up to and including 4.3.2)
Auth required
Prerequisites: WooCommerce registration enabled · Shop Manager-level access or higher · Crafted `yaymail_backup.zip` payload
devstral-2 · analyzed Apr 18, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0002
EPSS Percentile 5.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-02-18
CWE
CWE-862
Status published
Products (1)
yaycommerce/YayMail – WooCommerce Email Customizer < 4.3.2
Published Feb 18, 2026
Tracked Since Feb 18, 2026