WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WP Reroute Email

This plugin reroutes all outgoing emails from a WordPress site (sent using the wp_mail() function) to a predefined configurable email address.

3Reported vulnerabilities
7.2Highest CVSS score
1.5.2Latest version
1,000+Active installs

What to do now

Update WP Reroute Email to 1.5.0 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 6, 2025 / Tested up to WordPress: 6.8.8 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-27605 High 7.2 0.7% 1.4.6 and earlier 1.4.8 April 14, 2023
CVE-2023-3168 Medium 6.1 0.5% 1.4.9 and earlier 1.5.0 July 12, 2023
CVE-2023-27606 Medium 4.3 0.2% 1.4.6 and earlier 1.4.8 April 14, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.