Known vulnerabilities in Elastic Email Sender
Reconfigures wp_mail() to send email using Elastic Email API instead of SMTP.
2Reported vulnerabilities
4.4Highest CVSS score
1.2.22Latest version
10,000+Active installs
What to do now
Update Elastic Email Sender to 1.2.21 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2023-38387 | Medium | 0.4% | 1.2.6 and earlier | 1.2.7 |
July 20, 2023 |
| CVE-2025-66525 | Medium | 0.3% | 1.2.20 and earlier | 1.2.21 |
October 28, 2025 |