CVE-2026-39498HIGH NVDCVSS Score 7.2Severity HIGHPublished Jun 15, 2026Vendor unknownDescriptionShop manager PHP Object Injection in YayMail <= 4.3.3 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/yaymail/vulnerability/wordpress-yaymail-plugin-4-3-3-php-object-injection-vulnerability?_s_id=cve