
Ultimate WP Mail Security & Risk Analysis
wordpress.org/plugins/ultimate-wp-mailCustom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
Is Ultimate WP Mail Safe to Use in 2026?
Mostly Safe
Score 70/100Ultimate WP Mail is generally safe to use. 6 past CVEs were resolved. Keep it updated.
The ultimate-wp-mail plugin presents a mixed security posture. While it demonstrates some good practices such as a high percentage of prepared SQL statements and output escaping, significant concerns remain. The presence of 16 AJAX handlers with 3 lacking authentication checks creates a substantial attack surface for unauthorized actions. Furthermore, the taint analysis reveals 5 high-severity flows with unsanitized paths, indicating a potential for serious vulnerabilities like Cross-Site Scripting or SQL Injection if not properly handled.
The plugin's vulnerability history is concerning, with 6 known CVEs, including one high-severity unpatched vulnerability. The recurring types of vulnerabilities like Cross-site Scripting, Missing Authorization, CSRF, SQL Injection, and Open Redirect suggest a pattern of insecure input handling and authorization flaws that have not been fully remediated over time. The recent discovery of these issues in 2025 further highlights the ongoing security challenges.
In conclusion, while the plugin has strengths in its SQL and output sanitization, the unprotected AJAX endpoints, high-severity taint flows, and a history of critical vulnerability types, especially the unpatched high-severity CVE, pose significant risks. The developer needs to prioritize addressing these immediate threats and implementing more robust security measures to prevent recurring issues.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Unpatched high severity CVE
- Vulnerability history includes critical types
- Use of unserialize function
- Bundled library (TinyMCE)
Ultimate WP Mail Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Ultimate WP Mail <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ultimate WP Mail 1.0.17 - 1.3.6 - Missing Authorization to Authenticated (Contributor+) Privilege Escalation via get_email_log_details Function
Ultimate WP Mail <= 1.3.5 - Missing Authorization
Ultimate WP Mail <= 1.3.4 - Cross-Site Request Forgery
Ultimate WP Mail <= 1.3.4 - Authenticated (Contributor+) SQL Injection
Ultimate WP Mail <= 1.3.9 - Open Redirect
Ultimate WP Mail Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Ultimate WP Mail Attack Surface
AJAX Handlers 16
Shortcodes 1
WordPress Hooks 95
Maintenance & Trust
Ultimate WP Mail Maintenance & Trust
Maintenance Signals
Community Trust
Ultimate WP Mail Alternatives
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
Groundhogg — CRM, Newsletters, and Marketing Automation
groundhogg
Groundhogg is the best WordPress CRM & Marketing Automation plugin. Create flows, email campaigns, and have a CRM all within your WordPress site.
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
SALESmanago & Leadoo
salesmanago
AI-powered Customer Engagement Platform for impact-hungry eCommerce marketing teams
Ultimate WP Mail Developer Profile
21 plugins · 66K total installs
How We Detect Ultimate WP Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-wp-mail/css/blocks.css/wp-content/plugins/ultimate-wp-mail/css/admin.css/wp-content/plugins/ultimate-wp-mail/css/dashboard.css/wp-content/plugins/ultimate-wp-mail/css/bootstrap.css/wp-content/plugins/ultimate-wp-mail/css/bootstrap-theme.css/wp-content/plugins/ultimate-wp-mail/css/custom-element-style.css/wp-content/plugins/ultimate-wp-mail/css/froala_editor.pkgd.min.css/wp-content/plugins/ultimate-wp-mail/css/froala_style.min.css+20 more/wp-content/plugins/ultimate-wp-mail/js/froala_editor.pkgd.min.js/wp-content/plugins/ultimate-wp-mail/js/tinymce-plugin.js/wp-content/plugins/ultimate-wp-mail/js/tinymce.js/wp-content/plugins/ultimate-wp-mail/css/blocks.css?ver=/wp-content/plugins/ultimate-wp-mail/css/admin.css?ver=/wp-content/plugins/ultimate-wp-mail/css/dashboard.css?ver=/wp-content/plugins/ultimate-wp-mail/css/bootstrap.css?ver=/wp-content/plugins/ultimate-wp-mail/css/bootstrap-theme.css?ver=/wp-content/plugins/ultimate-wp-mail/css/custom-element-style.css?ver=/wp-content/plugins/ultimate-wp-mail/css/froala_editor.pkgd.min.css?ver=/wp-content/plugins/ultimate-wp-mail/css/froala_style.min.css?ver=/wp-content/plugins/ultimate-wp-mail/css/jquery.datetimepicker.css?ver=/wp-content/plugins/ultimate-wp-mail/css/new-admin-styles.css?ver=/wp-content/plugins/ultimate-wp-mail/css/select2.min.css?ver=/wp-content/plugins/ultimate-wp-mail/css/woocommerce.css?ver=/wp-content/plugins/ultimate-wp-mail/js/admin.js?ver=/wp-content/plugins/ultimate-wp-mail/js/admin-user-stats.js?ver=/wp-content/plugins/ultimate-wp-mail/js/blocks.js?ver=/wp-content/plugins/ultimate-wp-mail/js/custom-element-script.js?ver=/wp-content/plugins/ultimate-wp-mail/js/dashboard.js?ver=/wp-content/plugins/ultimate-wp-mail/js/installation-walkthrough.js?ver=/wp-content/plugins/ultimate-wp-mail/js/jquery.datetimepicker.js?ver=/wp-content/plugins/ultimate-wp-mail/js/new-admin-scripts.js?ver=/wp-content/plugins/ultimate-wp-mail/js/select2.full.min.js?ver=/wp-content/plugins/ultimate-wp-mail/js/tinymce-buttons.js?ver=/wp-content/plugins/ultimate-wp-mail/js/tinymce-plugin.js?ver=/wp-content/plugins/ultimate-wp-mail/js/tinymce.js?ver=/wp-content/plugins/ultimate-wp-mail/js/user-manager.js?ver=/wp-content/plugins/ultimate-wp-mail/js/woocommerce.js?ver=/wp-content/plugins/ultimate-wp-mail/js/wp-forms.js?ver=/wp-content/plugins/ultimate-wp-mail/js/froala_editor.pkgd.min.js?ver=HTML / DOM Fingerprints
ewd-uwpm-dashboard-sectionewd-uwpm-admin-formewd-uwpm-admin-fieldewd-uwpm-tabsewd-uwpm-tabewd-uwpm-tab-contentewd-uwpm-add-buttonewd-uwpm-list-table+28 more<!-- EWD UWPM Dashboard Section --><!-- EWD UWPM Admin Notice --><!-- EWD UWPM Review Ask Notice --><!-- EWD UWPM Getting Started Notice -->+1 moredata-ewd-uwpm-template-iddata-ewd-uwpm-template-typedata-ewd-uwpm-element-iddata-ewd-uwpm-actiondata-ewd-uwpm-nonceewd_uwpm_ajax_objectEWD_UWPM_varsEWD_UWPM_Admin_VarsEWD_UWPM_Admin_User_Stats_VarsEWD_UWPM_Blocks_VarsEWD_UWPM_Custom_Element_Vars+7 more