
ENL Newsletter Security & Risk Analysis
wordpress.org/plugins/enl-newsletterEasy to create multiple newsletters containing the blog latest posts.
Is ENL Newsletter Safe to Use in 2026?
Critical Risk — Avoid
Score 29/100ENL Newsletter is critically unsafe with 4 known CVEs, 4 still unpatched. Avoid in production.
The 'enl-newsletter' plugin version 1.0.1 exhibits a concerning security posture, primarily due to a significant history of vulnerabilities and several red flags in the static analysis. While the plugin presents a relatively small attack surface with no apparent unprotected AJAX handlers, REST API routes, or shortcodes, the presence of the `create_function` dangerous function and a high percentage of unsanitized paths in taint analysis are critical concerns. The output escaping is also severely lacking, with only 17% of outputs properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is particularly alarming, with four known CVEs, all of which remain unpatched, including a critical SQL injection and a CSRF vulnerability. This pattern of recurring and unaddressed vulnerabilities suggests a lack of commitment to secure coding practices and timely patching within the plugin's development. The existence of multiple critical and high-severity issues in past CVEs further amplifies the risk.
In conclusion, despite a seemingly limited direct attack surface, the 'enl-newsletter' plugin should be approached with extreme caution. The combination of poor output escaping, dangerous function usage, extensive unsanitized data flows, and a history of unpatched critical vulnerabilities makes it a significant security risk. Users are strongly advised to deactivate and seek alternative solutions until these issues are thoroughly addressed and verified.
Key Concerns
- Unpatched Critical CVE
- Unpatched High CVE
- Unpatched Medium CVE (x2)
- High severity taint flows (x9)
- Dangerous function: create_function
- Low output escaping percentage (17%)
- Unsanitized paths in taint analysis (11/11)
- No nonce checks
- No capability checks
ENL Newsletter Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
ENL Newsletter <= 1.0.1 - Authenticated (Admin+) SQL Injection
ENL Newsletter <= 1.0.1 - Cross-Site Request Forgery to Campaign Deletion
ENL Newsletter <= 1.0.1 - Cross-Site Request Forgery
ENL Newsletter <= 1.0.1 - Authenticated (Admin+) SQL Injection
ENL Newsletter Release Timeline
ENL Newsletter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
ENL Newsletter Attack Surface
WordPress Hooks 13
Scheduled Events 1
Maintenance & Trust
ENL Newsletter Maintenance & Trust
Maintenance Signals
Community Trust
ENL Newsletter Alternatives
Bulk Term Generator – Import multiple tags, categories, and taxonomies easily
bulk-term-generator
Streamline taxonomy management in WordPress with Bulk Term Generator, your free tool for easy, bulk term importing.
Weekly Schedule
weekly-schedule
The purpose of this plugin is to allow users to create a schedule of weekly events and display that schedule on a page in a table form.
Simple Category Posts
simple-seo-categories-posts
A plugin to display posts in a widget with title, thumb, excerpt, date and author.
Polylang Category Creator
polylang-category-creator
Polylang extension to create categories for all languages in one page. It detects your languages and taxonomies to get things done easier.
Archive Post Order Plus
archive-post-order-plus
A plugin that sets the display order of posts. 投稿の表示順を設定するプラグイン。
ENL Newsletter Developer Profile
16 plugins · 220 total installs
How We Detect ENL Newsletter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enl-newsletter/css/style.css/wp-content/plugins/enl-newsletter/js/script.js/wp-content/plugins/enl-newsletter/js/script.jsenl-newsletter/css/style.css?ver=enl-newsletter/js/script.js?ver=HTML / DOM Fingerprints
enl_formdata-enl-id