Vulnerabilities and security researches forwp-mail-logging wp-mail-logging
Direction: descendingSep 18, 2026
WP Mail Logging # PSC-2026-65696
- PSC, Research URL
- Home page URL
- Application
- Date
- Sep 18, 2026
- Research Description
- Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.
- Affected versions
-
Min 1.16.0, max 1.16.0.
- Status
-
SAFE & CERTIFIED
Jun 16, 2026
WP Mail Logging # 16a4582a65ef1c749500b25a8972af811c2b8de7
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 11, 2017
- Research Description
- WP Mail Logging [wp-mail-logging] < 1.8.3 WP Mail Logging <= 1.8.2 - Cross-Site Scripting The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extractMessage’ and 'column_default' functions in versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.8.3.
- Status
-
vulnerable
WP Mail Logging # 25792919c2f5c1af94cee76ff90b5871ca0d7e37
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 23, 2023
- Research Description
- WP Mail Logging [wp-mail-logging] < 1.12.0 WP Mail Logging <= 1.11.2 - Missing Authorization to Notice Dismissal The WP Mail Logging plugin for WordPress is vulnerable to unauthorized notice dismissal due to a missing capability check on the feedback_notice_dismiss() function in versions up to, and including, 1.11.2. This makes it possible for authenticated attackers with subscriber-level access and above to dismiss plugin notices.
- Affected versions
-
max 1.12.0.
- Status
-
vulnerable
WP Mail Logging # f673de5eace2d78fe63138c4deed53981120c95f
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 20, 2017
- Research Description
- WP Mail Logging [wp-mail-logging] < 1.8.3 WordPress WP Mail Logging plugin <=1.8.2 - Stored Cross-Site Scripting (XSS) vulnerability Stored Cross-Site Scripting (XSS) vulnerability found by Yehuda in WordPress WP Mail Logging plugin (versions <=1.8.2).
- Affected versions
-
max 1.8.3.
- Status
-
vulnerable
WP Mail Logging # ff320b0a3bb93f100730eeb0322346e556a35a21
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 29, 2021
- Research Description
- WP Mail Logging [wp-mail-logging] < 1.10.0 WP Mail Logging < 1.10.0 - Unauthenticated Arbitrary Settings Change The WP Mail Logging plugin for WordPress is vulnerable to arbitrary settings change in versions before 1.10.0. This is due to the plugin using an outdated version of the Redux Framework. This makes it possible for unauthenticated attackers to arbitrarily change some plugin settings.
- Affected versions
-
max 1.10.0.
- Status
-
vulnerable
WP Mail Logging # 0cc11fdb666f5be9bc661517d8e97abf61e68bbc
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 26, 2023
- Research Description
- WP Mail Logging [wp-mail-logging] < 1.12.0 WordPress WP Mail Logging Plugin < 1.12.0 is vulnerable to Broken Access Control Update the WordPress WP Mail Logging plugin to the latest available version (at least 1.12.0). Unknown discovered and reported this Broken Access Control vulnerability in WordPress WP Mail Logging Plugin. This vulnerability has been fixed in version 1.12.0.
- Affected versions
-
max 1.12.0.
- Status
-
vulnerable
WP Mail Logging # 8ff377db-08f9-4d98-af49-43dcbfcd98b5
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Mail Logging [wp-mail-logging] < 1.8.3 WP Mail Logging <= 1.8.2 - Stored Cross-Site Scripting The WP Mail Logging by MailPoet WordPress plugin was affected by a Stored Cross-Site Scripting security vulnerability.
- Affected versions
-
max 1.8.3.
- Status
-
vulnerable
Apr 14, 2026
WP Mail Logging # CVE-2026-2471
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2026
- Research Description
- The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrieved from the database without validation. This makes it possible for unauthenticated attackers to inject a PHP Object by submitting a double-serialized payload through any public-facing form that sends email (e.g., Contact Form 7). When the email is logged and subsequently viewed by an administrator, the malicious payload is deserialized into an arbitrary PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
- Affected versions
-
max 1.16.
- Status
-
vulnerable
Jun 07, 2024
WP Mail Logging # CVE-2023-3081
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 12, 2023
- Research Description
- The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.
- Affected versions
-
max 1.11.2.
- Status
-
vulnerable