Ultimate WP Mail <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ultimate WP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.9
- Disclosed:
- Sep 22, 2025
CVE-2025-53454 on NVD →
Ultimate WP Mail 1.0.17 - 1.3.6 - Missing Authorization to Authenticated (Contributor+) Privilege Escalation via get_email_log_details Function
high
The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corresponding email log post content (including the password-reset li...
- CVSS:
- 7.5
- Affected:
- 1.0.17 – 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Jul 15, 2025
CVE-2025-6993 on NVD →
Ultimate WP Mail [ultimate-wp-mail] < 1.3.6
unknown
[en] Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate WP Mail: from n/a through 1.3.5.
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Jun 6, 2025
CVE-2025-49288 on NVD →
Ultimate WP Mail <= 1.3.5 - Missing Authorization
medium
The Ultimate WP Mail plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Jun 5, 2025
CVE-2025-49288 on NVD →
Ultimate WP Mail <= 1.3.4 - Authenticated (Contributor+) SQL Injection
medium
The Ultimate WP Mail plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access an...
- CVSS:
- 6.5
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- May 7, 2025
CVE-2025-47490 on NVD →
Ultimate WP Mail <= 1.3.4 - Cross-Site Request Forgery
medium
The Ultimate WP Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on the save_email_lists() function. This makes it possible for unauthenticated attackers to update email lists via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- May 7, 2025
CVE-2025-47466 on NVD →
Ultimate WP Mail [ultimate-wp-mail] < 1.3.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- May 7, 2025
CVE-2025-47466 on NVD →
Ultimate WP Mail [ultimate-wp-mail] < 1.3.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail allows SQL Injection. This issue affects Ultimate WP Mail: from n/a through 1.3.4.
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- May 7, 2025
CVE-2025-47490 on NVD →
Ultimate WP Mail <= 1.3.9 - Open Redirect
medium
The Ultimate WP Mail plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.9. This is due to insufficient validation on a redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick th...
- CVSS:
- 6.1
- Affected:
- up to 1.3.9
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32694 on NVD →
Ultimate WP Mail [ultimate-wp-mail] <= 1.3.5 (unfixed)
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Rustaurius Ultimate WP Mail allows Phishing. This issue affects Ultimate WP Mail: from n/a through 1.3.2.
- Affected:
- up to 1.3.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32694 on NVD →
Ultimate WP Mail [ultimate-wp-mail] < 1.3.7
unknown
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
CVE-2025-6993 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database