Event Espresso – Custom Email Template Shortcode Security & Risk Analysis

wordpress.org/plugins/email-shortcode

Create a Custom Shortcode for Default Message Template of Event Espresso.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Oct 4, 2023
e-shortcodesemail-shortcodesevent-espressomessage-templatetemplate-shortcodes
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 14, 2025
Safety Verdict

Is Event Espresso – Custom Email Template Shortcode Safe to Use in 2026?

Use With Caution

Score 64/100

Event Espresso – Custom Email Template Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 14, 2025Updated 2yr ago
Risk Assessment

The "email-shortcode" plugin version 1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. The presence of nonce checks and a low number of total entry points are also encouraging signs. However, the static analysis reveals that 29% of output operations are not properly escaped, which presents a potential Cross-Site Scripting (XSS) risk. Furthermore, the absence of capability checks on any entry points means that if any were discovered, they could be accessed by any user. The vulnerability history is a significant concern, with one unpatched medium-severity CVE related to XSS. The fact that the last vulnerability was in the near future (2025) and is still unpatched strongly suggests that the plugin is not actively maintained or that the developer is not addressing known security flaws promptly. While the code itself has some strengths, the unpatched vulnerability and the potential for unescaped output create a notable risk that requires immediate attention.

Key Concerns

  • Unpatched medium severity CVE
  • Unescaped output (29%)
  • No capability checks on entry points
Vulnerabilities
1 published

Event Espresso – Custom Email Template Shortcode Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32507medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Event Espresso – Custom Email Template Shortcode <= 1.0.0 - Reflected Cross-Site Scripting

Apr 14, 2025Unpatched
Version History

Event Espresso – Custom Email Template Shortcode Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Event Espresso – Custom Email Template Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
23
57 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

71% escaped80 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
<add_new_e-shortcodes> (admin/partials/add_new_e-shortcodes.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Event Espresso – Custom Email Template Shortcode Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes/class-ee-email-shortcode.php:139
actionadmin_enqueue_scriptsincludes/class-ee-email-shortcode.php:154
actionadmin_enqueue_scriptsincludes/class-ee-email-shortcode.php:155
actionadmin_menuincludes/class-ee-email-shortcode.php:157
filteradmin_footer_textincludes/class-ee-email-shortcode.php:163
filterFHEE__EE_Shortcodes__shortcodesincludes/class-ee-email-shortcode.php:168
filterFHEE__EE_Shortcodes__parser_afterincludes/class-ee-email-shortcode.php:169
actionwp_enqueue_scriptsincludes/class-ee-email-shortcode.php:184
actionwp_enqueue_scriptsincludes/class-ee-email-shortcode.php:185
Maintenance & Trust

Event Espresso – Custom Email Template Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 4, 2023
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Event Espresso – Custom Email Template Shortcode Developer Profile

Aakif Kadiwala

4 plugins · 50 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Event Espresso – Custom Email Template Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-shortcode/admin/css/ee-email-shortcode-admin.css/wp-content/plugins/email-shortcode/admin/js/ee-email-shortcode-admin.js
Script Paths
/wp-content/plugins/email-shortcode/admin/js/ee-email-shortcode-admin.js
Version Parameters
ee-email-shortcode-admin.css?ver=ee-email-shortcode-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
eees_menu-title-tag
FAQ

Frequently Asked Questions about Event Espresso – Custom Email Template Shortcode