plugin

Ultimate Wp Mail Vulnerabilities

11 known security issues reported for the Ultimate Wp Mail WordPress plugin. Most recent disclosed Sep 22, 2025.

1 high 5 medium

Running Ultimate Wp Mail on your site? Check whether your installed version is affected.

Scan your site free

Ultimate WP Mail <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ultimate WP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.3.8
Fixed in:
1.3.9
Disclosed:
Sep 22, 2025

CVE-2025-53454 on NVD →

Ultimate WP Mail 1.0.17 - 1.3.6 - Missing Authorization to Authenticated (Contributor+) Privilege Escalation via get_email_log_details Function

high

The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corresponding email log post content (including the password-reset li...

CVSS:
7.5
Affected:
1.0.17 – 1.3.6
Fixed in:
1.3.7
Disclosed:
Jul 15, 2025

CVE-2025-6993 on NVD →

Ultimate WP Mail [ultimate-wp-mail] < 1.3.6

unknown

[en] Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate WP Mail: from n/a through 1.3.5.

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Jun 6, 2025

CVE-2025-49288 on NVD →

Ultimate WP Mail <= 1.3.5 - Missing Authorization

medium

The Ultimate WP Mail plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.3.5
Fixed in:
1.3.6
Disclosed:
Jun 5, 2025

CVE-2025-49288 on NVD →

Ultimate WP Mail <= 1.3.4 - Authenticated (Contributor+) SQL Injection

medium

The Ultimate WP Mail plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access an...

CVSS:
6.5
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
May 7, 2025

CVE-2025-47490 on NVD →

Ultimate WP Mail <= 1.3.4 - Cross-Site Request Forgery

medium

The Ultimate WP Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on the save_email_lists() function. This makes it possible for unauthenticated attackers to update email lists via a forged request granted...

CVSS:
4.3
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
May 7, 2025

CVE-2025-47466 on NVD →

Ultimate WP Mail [ultimate-wp-mail] < 1.3.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
May 7, 2025

CVE-2025-47466 on NVD →

Ultimate WP Mail [ultimate-wp-mail] < 1.3.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail allows SQL Injection. This issue affects Ultimate WP Mail: from n/a through 1.3.4.

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
May 7, 2025

CVE-2025-47490 on NVD →

Ultimate WP Mail <= 1.3.9 - Open Redirect

medium

The Ultimate WP Mail plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.9. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick th...

CVSS:
6.1
Affected:
up to 1.3.9
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32694 on NVD →

Ultimate WP Mail [ultimate-wp-mail] <= 1.3.5 (unfixed)

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Rustaurius Ultimate WP Mail allows Phishing. This issue affects Ultimate WP Mail: from n/a through 1.3.2.

Affected:
up to 1.3.5
Fix:
No patched version reported
Disclosed:
Apr 9, 2025

CVE-2025-32694 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database