CleverReach® WP Security & Risk Analysis

wordpress.org/plugins/cleverreach-wp

Connect your WordPress account with our easy-to-use email software and increase the success of your website or blog with newsletter marketing!

4K active installs v1.5.23 PHP 5.3+ WP 4.9+ Updated Jan 28, 2026
email-automationemail-marketing-toolintegrationmarketing-automationnewsletter
94
A · Safe
CVEs total2
Unpatched0
Last CVEJan 15, 2026
Safety Verdict

Is CleverReach® WP Safe to Use in 2026?

Generally Safe

Score 94/100

CleverReach® WP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Jan 15, 2026Updated 3mo ago
Risk Assessment

The cleverreach-wp plugin v1.5.23 exhibits a mixed security posture. While it demonstrates good practices in output escaping and SQL query preparedness, with a high percentage of outputs being properly escaped and a significant portion of SQL queries using prepared statements, there are notable areas of concern. The presence of the `unserialize` function is a significant risk signal, as it can lead to object injection vulnerabilities if not handled with extreme care and strict validation of the serialized data. The complete absence of nonce checks across all entry points, especially with a limited but present attack surface, is a major weakness. Furthermore, the plugin has a history of known high-severity vulnerabilities, specifically SQL injection, indicating potential for recurring issues in how external data is handled. While there are currently no unpatched CVEs, the historical pattern of high-severity SQL injection vulnerabilities is a strong indicator of past weaknesses that could resurface or be exploited in similar ways.

Key Concerns

  • Presence of 'unserialize' function
  • Zero nonce checks
  • History of 2 high severity CVEs
  • SQL Injection vulnerability type history
Vulnerabilities
2 published

CleverReach® WP Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
2

2 total CVEs

CVE-2025-68034high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CleverReach® WP <= 1.5.21 - Unauthenticated SQL Injection

Jan 15, 2026 Patched in 1.5.22 (16d)
CVE-2025-7036high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CleverReach WP <= 1.5.20 - Unauthenticated SQL Injection via title Parameter

Aug 5, 2025 Patched in 1.5.21 (13d)
Version History

CleverReach® WP Release Timeline

Code Analysis
Analyzed Mar 16, 2026

CleverReach® WP Code Analysis

Dangerous Functions
1
Raw SQL Queries
10
19 prepared
Unescaped Output
9
341 escaped
Nonce Checks
0
Capability Checks
1
File Operations
10
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserializereturn unserialize( $process['runner'] );Components\Repositories\class-process-repository.php:61

SQL Query Safety

66% prepared29 total queries

Output Escaping

97% escaped350 total outputs
Attack Surface

CleverReach® WP Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cleverreach] Components\class-shortcode-handler.php:34
WordPress Hooks 38
actionadmin_noticesclass-plugin.php:123
actionwidgets_initclass-plugin.php:155
filterblock_categories_allclass-plugin.php:159
filterblock_categoriesclass-plugin.php:161
actionenqueue_block_editor_assetsclass-plugin.php:164
filtertiny_mce_before_initclass-plugin.php:265
filtermce_buttonsclass-plugin.php:266
filtermce_external_pluginsclass-plugin.php:267
filterwidget_textclass-plugin.php:270
filterwidget_textclass-plugin.php:271
actioninitclass-plugin.php:461
actionadmin_initclass-plugin.php:462
actionupgrader_process_completeclass-plugin.php:463
filterquery_varsclass-plugin.php:464
actiontemplate_redirectclass-plugin.php:465
actionadmin_initclass-plugin.php:477
actionwpcf7_initclass-plugin.php:478
actionwpcf7_editor_panelsclass-plugin.php:479
actionwpcf7_after_saveclass-plugin.php:480
actionafter_delete_postclass-plugin.php:481
actionwpcf7_submitclass-plugin.php:482
actionadmin_menuclass-plugin.php:491
actionuser_new_formclass-plugin.php:494
actionshow_user_profileclass-plugin.php:495
actionedit_user_profileclass-plugin.php:496
actionadmin_headclass-plugin.php:621
actionadd_user_to_blogComponents\class-hook-handler.php:76
actionprofile_updateComponents\class-hook-handler.php:77
actionremove_user_from_blogComponents\class-hook-handler.php:78
actiongrant_super_adminComponents\class-hook-handler.php:79
actionrevoke_super_adminComponents\class-hook-handler.php:80
actiondelete_blogComponents\class-hook-handler.php:81
actionuser_registerComponents\class-hook-handler.php:83
actionprofile_updateComponents\class-hook-handler.php:84
actiondelete_userComponents\class-hook-handler.php:85
actionure_user_permissions_updateComponents\class-hook-handler.php:88
actionset_user_roleComponents\class-hook-handler.php:89
actionupdated_optionComponents\class-hook-handler.php:90
Maintenance & Trust

CleverReach® WP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version5.3
Downloads85K

Community Trust

Rating66/100
Number of ratings7
Active installs4K
Developer Profile

CleverReach® WP Developer Profile

CleverReach®

3 plugins · 6K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
82 days
View full developer profile
Detection Fingerprints

How We Detect CleverReach® WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cleverreach-wp/resources/css/cleverreach.css/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.backend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.frontend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.gutenberg-block.js
Script Paths
/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.backend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.frontend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.gutenberg-block.js
Version Parameters
cleverreach-wp/resources/css/cleverreach.css?ver=cleverreach-wp/resources/js/cleverreach.backend.js?ver=cleverreach-wp/resources/js/cleverreach.frontend.js?ver=cleverreach-wp/resources/js/cleverreach.gutenberg-block.js?ver=

HTML / DOM Fingerprints

CSS Classes
cleverreach-subscribe-form-wrappercleverreach-wp-widget-containercleverreach-frontend-form
HTML Comments
<!-- CleverReach Form Start --><!-- CleverReach Form End -->
Data Attributes
data-cleverreach-form-iddata-cleverreach-render-form
JS Globals
window.CleverReach
Shortcode Output
[cleverreach_subscription_form]
FAQ

Frequently Asked Questions about CleverReach® WP