CVE-2022-46821 MEDIUM

CVE-2022-46821: WordPress Emails & Newsletters with Jackmail Plugin <= 1.2.22 is vulnerable to CSV Injection

Vendor Jackmail & Sarbacane
Product Emails & Newsletters with Jackmail
Weakness CWE-1236
Published November 7, 2023
Last update April 28, 2026

CVSS base score

5.8/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane Emails & Newsletters with Jackmail.This issue affects Emails & Newsletters with Jackmail: from n/a through 1.2.22.

Explanation of Vulnerability in Simple Terms

02Summary

Emails & Newsletters with Jackmail versions up to 1.2.22 contain an integrity vulnerability allowing authenticated users with low privileges to modify content when a victim visits a malicious link. The vulnerability requires user interaction and affects the integrity of data across the application scope. No confidentiality or availability impact.

What an attacker can do

03Attacker Capabilities

Modify application data or content when a low-privilege authenticated user visits a crafted link.

Potential impact on your site

04Site Impact

Authenticated users with low privileges can alter site content or data if tricked into visiting a malicious link.

Conditions required to exploit

05Prerequisites

Attacker needs low-privilege account access; victim must click a malicious link or visit attacker-controlled page.

Key dates

06Disclosure timeline

November 7, 2023 CVE published
April 28, 2026 Record updated