EnvíaloSimple: Email Marketing y Newsletters Security & Risk Analysis

wordpress.org/plugins/envialosimple-email-marketing-y-newsletters-gratis

El plugin de EnvíaloSimple te permitirá crear y enviar Newsletters de calidad profesional, en minutos y directamente desde tu Wordpress.

2K active installs v2.4.5 PHP 7.0+ WP 5.9.3+ Updated Apr 8, 2025
editor-visualemailemail-marketingenvialosimplenewsletter
90
A · Safe
CVEs total5
Unpatched0
Last CVEApr 16, 2024
Safety Verdict

Is EnvíaloSimple: Email Marketing y Newsletters Safe to Use in 2026?

Generally Safe

Score 90/100

EnvíaloSimple: Email Marketing y Newsletters has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

5 known CVEsLast CVE: Apr 16, 2024Updated 1yr ago
Risk Assessment

The plugin 'envialosimple-email-marketing-y-newsletters-gratis' v2.4.5 exhibits a mixed security posture. While it boasts a large number of REST API entry points (31), importantly, none of them appear to be unprotected by permission callbacks, which is a strong security practice. The code also demonstrates good practices in output escaping (93%) and uses prepared statements for a significant portion of its SQL queries. However, the presence of a `unserialize` dangerous function, coupled with two critical taint flows, raises concerns about potential deserialization vulnerabilities if user-controlled data is not rigorously sanitized before being unserialized.

The vulnerability history reveals a concerning pattern with a total of 5 known CVEs, including high and medium severity issues like Unrestricted File Upload, CSRF, Deserialization of Untrusted Data, and Cross-Site Scripting. Although there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests a potential for undiscovered or newly introduced vulnerabilities in this codebase. The most recent vulnerability was identified only recently in April 2024, emphasizing the need for ongoing vigilance.

In conclusion, while the plugin has implemented some key security measures like permission checks on its REST API and good output escaping, the presence of dangerous functions, critical taint flows, and a history of diverse and serious vulnerabilities necessitate a cautious approach. Developers should prioritize addressing the identified taint flows and thoroughly review all deserialization points. Users should ensure they are using the latest patched versions and remain aware of the plugin's past security incidents.

Key Concerns

  • Presence of 'unserialize' dangerous function
  • Critical taint flow detected (2 instances)
  • Known CVEs: 1 high, 4 medium
  • Flows with unsanitized paths (11 instances)
  • SQL queries: 50% not using prepared statements
Vulnerabilities
5 published

EnvíaloSimple: Email Marketing y Newsletters Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
2 CVEs in 2023
2023
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
4

5 total CVEs

CVE-2024-32587medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EnvíaloSimple: Email Marketing y Newsletters <= 2.2 - Reflected Cross-Site Scripting

Apr 16, 2024 Patched in 2.3 (9d)
CVE-2024-2125high · 8.8Unrestricted Upload of File with Dangerous Type

EnvíaloSimple: Email Marketing y Newsletters <= 2.3 - Cross-Site Request Forgery to Arbitrary File Upload

Apr 1, 2024 Patched in 2.4 (16d)
CVE-2023-51416medium · 4.3Cross-Site Request Forgery (CSRF)

EnvíaloSimple <= 2.2 - Cross-Site Request Forgery

Dec 27, 2023 Patched in 2.3 (162d)
CVE-2023-51414medium · 6.5Deserialization of Untrusted Data

EnvíaloSimple <= 2.1 Unauthenticated PHP Object Injection

Dec 27, 2023 Patched in 2.2 (27d)
CVE-2014-4527medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EnvialoSimple: Email Marketing y Newsletters < 1.98 - Cross-Site Scripting

May 28, 2014 Patched in 1.98 (3527d)
Version History

EnvíaloSimple: Email Marketing y Newsletters Release Timeline

Code Analysis
Analyzed Mar 16, 2026

EnvíaloSimple: Email Marketing y Newsletters Code Analysis

Dangerous Functions
1
Raw SQL Queries
2
2 prepared
Unescaped Output
42
539 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

unserialize$dataNewContact = unserialize($token, array('allowed_classes' => false));pages\frontend\suscription.php:15

SQL Query Safety

50% prepared4 total queries

Output Escaping

93% escaped581 total outputs
Data Flows · Security
11 unsanitized

Data Flow Analysis

12 flows11 with unsanitized paths
campaigns_getbyid (api\campaigns.php:96)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EnvíaloSimple: Email Marketing y Newsletters Attack Surface

Entry Points31
Unprotected0

REST API Routes 31

GET/wp-json/envialosimple/v1/campaigns/getallapi\campaigns.php:5
GET/wp-json/envialosimple/v1/campaigns/getbyidapi\campaigns.php:12
POST/wp-json/envialosimple/v1/campaigns/createapi\campaigns.php:19
POST/wp-json/envialosimple/v1/campaigns/editapi\campaigns.php:26
GET/wp-json/envialosimple/v1/campaigns/deleteapi\campaigns.php:33
POST/wp-json/envialosimple/v1/campaigns/sendpreviewapi\campaigns.php:40
POST/wp-json/envialosimple/v1/campaigns/checkstatusapi\campaigns.php:47
POST/wp-json/envialosimple/v1/campaigns/sendapi\campaigns.php:54
GET/wp-json/envialosimple/v1/contactsform7/getFormsapi\contactform7.php:5
GET/wp-json/envialosimple/v1/contactsform7/getFieldsByIdapi\contactform7.php:15
POST/wp-json/envialosimple/v1/contactsform7/getFormByIdapi\contactform7.php:24
GET/wp-json/envialosimple/v1/contactsform7/getConfigapi\contactform7.php:34
POST/wp-json/envialosimple/v1/contactsform7/setConfigapi\contactform7.php:43
POST/wp-json/envialosimple/v1/contactsform7/getAllConfigsapi\contactform7.php:52
POST/wp-json/envialosimple/v1/contactsform7/deleteByIdapi\contactform7.php:61
GET/wp-json/envialosimple/v1/contacts/getallapi\contacts.php:5
GET/wp-json/envialosimple/v1/contacts/getbyidapi\contacts.php:12
POST/wp-json/envialosimple/v1/contacts/createapi\contacts.php:19
POST/wp-json/envialosimple/v1/contacts/editapi\contacts.php:26
POST/wp-json/envialosimple/v1/contacts/deleteapi\contacts.php:33
POST/wp-json/envialosimple/v1/contacts/suscribeapi\contacts.php:40
GET/wp-json/envialosimple/v1/customfields/getallapi\customfields.php:5
POST/wp-json/envialosimple/v1/gallery/addapi\gallery.php:6
POST/wp-json/envialosimple/v1/gallery/getallapi\gallery.php:16
GET/wp-json/envialosimple/v1/lists/getallapi\lists.php:5
GET/wp-json/envialosimple/v1/lists/getbyidapi\lists.php:12
GET/wp-json/envialosimple/v1/lists/deleteapi\lists.php:19
POST/wp-json/envialosimple/v1/lists/createapi\lists.php:26
POST/wp-json/envialosimple/v1/lists/editapi\lists.php:34
GET/wp-json/envialosimple/v1/posts/getallapi\posts.php:5
GET/wp-json/envialosimple/v1/segments/getallapi\segments.php:5
WordPress Hooks 23
actionrest_api_initapi\campaigns.php:4
actionrest_api_initapi\contactform7.php:4
actionrest_api_initapi\contactform7.php:14
actionrest_api_initapi\contactform7.php:23
actionrest_api_initapi\contactform7.php:33
actionrest_api_initapi\contactform7.php:42
actionrest_api_initapi\contactform7.php:51
actionrest_api_initapi\contactform7.php:60
actionrest_api_initapi\contacts.php:4
actionrest_api_initapi\customfields.php:4
actionrest_api_initapi\gallery.php:5
actionrest_api_initapi\gallery.php:15
actioninitapi\index.php:6
actionrest_api_initapi\lists.php:4
actionrest_api_initapi\posts.php:4
actionrest_api_initapi\segments.php:4
actionadmin_initassets.php:19
actionadmin_initassets.php:46
actionwpcf7_mail_senthooks\contactform7.php:3
actionplugins_loadedindex.php:30
actionadmin_menumenu.php:3
actioninitpages\frontend\suscription.php:2
filterthe_postspages\frontend\suscription.php:7
Maintenance & Trust

EnvíaloSimple: Email Marketing y Newsletters Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 8, 2025
PHP min version7.0
Downloads143K

Community Trust

Rating100/100
Number of ratings9
Active installs2K
Developer Profile

EnvíaloSimple: Email Marketing y Newsletters Developer Profile

DonWeb

2 plugins · 2K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
748 days
View full developer profile
Detection Fingerprints

How We Detect EnvíaloSimple: Email Marketing y Newsletters

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/styles/menu.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/styles/styles.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/grapes/css/grapes.min.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/grapes/preset/grapesjs-preset-newsletter.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/axios.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/vue.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/dual-listbox.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/datepicker/vue-datepicker.js+9 more
Script Paths
/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/axios.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/vue.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/dual-listbox.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/datepicker/vue-datepicker.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/datepicker/es.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/grapes/grapes.min.js+7 more

HTML / DOM Fingerprints

JS Globals
ES_PLUGIN_URL_BASE
REST Endpoints
/wp-json/envialosimple/v1/campaigns/getall/wp-json/envialosimple/v1/campaigns/getbyid/wp-json/envialosimple/v1/campaigns/create/wp-json/envialosimple/v1/campaigns/edit/wp-json/envialosimple/v1/campaigns/delete/wp-json/envialosimple/v1/campaigns/sendpreview/wp-json/envialosimple/v1/campaigns/checkstatus/wp-json/envialosimple/v1/campaigns/send
FAQ

Frequently Asked Questions about EnvíaloSimple: Email Marketing y Newsletters