cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-mail-logging wp-mail-logging

Direction: descending
Sep 18, 2026

WP Mail Logging # PSC-2026-65696

PSC, Research URL

PSC-2026-65696

Application

WP Mail Logging

Date
Sep 18, 2026
Research Description
Email logging plugins retain message bodies, recipient details, headers, attachments, and delivery errors that may contain sensitive operational data. WP Mail Logging version 1.16.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-65696. The review focused on log access, stored message rendering, attachment references, search and bulk actions, resend requests, and protection of plugin settings.
Affected versions
Min 1.16.0, max 1.16.0.
Status
SAFE & CERTIFIED
Jun 16, 2026

WP Mail Logging # 16a4582a65ef1c749500b25a8972af811c2b8de7

Application

WP Mail Logging

Date
Nov 11, 2017
Research Description
WP Mail Logging [wp-mail-logging] < 1.8.3 WP Mail Logging <= 1.8.2 - Cross-Site Scripting The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extractMessage’ and 'column_default' functions in versions up to, and including, 1.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.8.3.
Status
vulnerable

WP Mail Logging # 25792919c2f5c1af94cee76ff90b5871ca0d7e37

Application

WP Mail Logging

Date
Jun 23, 2023
Research Description
WP Mail Logging [wp-mail-logging] < 1.12.0 WP Mail Logging <= 1.11.2 - Missing Authorization to Notice Dismissal The WP Mail Logging plugin for WordPress is vulnerable to unauthorized notice dismissal due to a missing capability check on the feedback_notice_dismiss() function in versions up to, and including, 1.11.2. This makes it possible for authenticated attackers with subscriber-level access and above to dismiss plugin notices.
Affected versions
max 1.12.0.
Status
vulnerable

WP Mail Logging # f673de5eace2d78fe63138c4deed53981120c95f

Application

WP Mail Logging

Date
Nov 20, 2017
Research Description
WP Mail Logging [wp-mail-logging] < 1.8.3 WordPress WP Mail Logging plugin <=1.8.2 - Stored Cross-Site Scripting (XSS) vulnerability Stored Cross-Site Scripting (XSS) vulnerability found by Yehuda in WordPress WP Mail Logging plugin (versions <=1.8.2).
Affected versions
max 1.8.3.
Status
vulnerable

WP Mail Logging # ff320b0a3bb93f100730eeb0322346e556a35a21

Application

WP Mail Logging

Date
Nov 29, 2021
Research Description
WP Mail Logging [wp-mail-logging] < 1.10.0 WP Mail Logging < 1.10.0 - Unauthenticated Arbitrary Settings Change The WP Mail Logging plugin for WordPress is vulnerable to arbitrary settings change in versions before 1.10.0. This is due to the plugin using an outdated version of the Redux Framework. This makes it possible for unauthenticated attackers to arbitrarily change some plugin settings.
Affected versions
max 1.10.0.
Status
vulnerable

WP Mail Logging # 0cc11fdb666f5be9bc661517d8e97abf61e68bbc

Application

WP Mail Logging

Date
Jun 26, 2023
Research Description
WP Mail Logging [wp-mail-logging] < 1.12.0 WordPress WP Mail Logging Plugin < 1.12.0 is vulnerable to Broken Access Control Update the WordPress WP Mail Logging plugin to the latest available version (at least 1.12.0). Unknown discovered and reported this Broken Access Control vulnerability in WordPress WP Mail Logging Plugin. This vulnerability has been fixed in version 1.12.0.
Affected versions
max 1.12.0.
Status
vulnerable

WP Mail Logging # 8ff377db-08f9-4d98-af49-43dcbfcd98b5

Application

WP Mail Logging

Date
-
Research Description
WP Mail Logging [wp-mail-logging] < 1.8.3 WP Mail Logging &lt;= 1.8.2 - Stored Cross-Site Scripting The WP Mail Logging by MailPoet WordPress plugin was affected by a Stored Cross-Site Scripting security vulnerability.
Affected versions
max 1.8.3.
Status
vulnerable
Apr 14, 2026

WP Mail Logging # CVE-2026-2471

CVE, Research URL

CVE-2026-2471

Application

WP Mail Logging

Date
Feb 28, 2026
Research Description
The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retrieved from the database without validation. This makes it possible for unauthenticated attackers to inject a PHP Object by submitting a double-serialized payload through any public-facing form that sends email (e.g., Contact Form 7). When the email is logged and subsequently viewed by an administrator, the malicious payload is deserialized into an arbitrary PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Affected versions
max 1.16.
Status
vulnerable
Jun 07, 2024

WP Mail Logging # CVE-2023-3081

CVE, Research URL

CVE-2023-3081

Application

WP Mail Logging

Date
Jul 12, 2023
Research Description
The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: An incomplete fix was released in 1.11.1.
Affected versions
max 1.11.2.
Status
vulnerable