
Mailing Group Listserv Security & Risk Analysis
wordpress.org/plugins/wp-mailing-groupCreates a Mailing Group on your site to which users can subscribe, messages sent to the group's email address will be forwarded to all members.
Is Mailing Group Listserv Safe to Use in 2026?
Mostly Safe
Score 74/100Mailing Group Listserv is generally safe to use. 4 past CVEs were resolved. Keep it updated.
The wp-mailing-group plugin v3.0.5 presents a concerning security posture due to a significant number of unprotected AJAX handlers. With 7 out of 7 AJAX handlers lacking authentication checks, this creates a wide attack surface for unauthorized actions. Furthermore, the presence of 5 high-severity taint flows indicates potential for serious vulnerabilities if user input is not properly handled before being used in sensitive operations. The plugin's vulnerability history, with 4 known CVEs and one still unpatched, including common issues like SQL injection and XSS, suggests a pattern of security weaknesses that have not been fully addressed. While the plugin demonstrates good practices in using prepared statements for SQL queries and performing proper output escaping, these strengths are overshadowed by the critical lack of authentication on AJAX endpoints and the ongoing unpatched vulnerability.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unpatched CVEs
- Bundled outdated PHPMailer
- Dangerous unserialize function used
Mailing Group Listserv Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Mailing Group Listserv <= 3.0.5 - Cross-Site Request Forgery
Mailing Group Listserv <= 3.0.4 - Authenticated (Subscriber+) SQL Injection
Mailing Group Listserv <= 2.0.9 - Authenticated (Administrator+) SQL Injection
Mailing Group Listserv <= 2.0.9 - Reflected Cross-Site Scripting
Mailing Group Listserv Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Mailing Group Listserv Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 21
Scheduled Events 4
Maintenance & Trust
Mailing Group Listserv Maintenance & Trust
Maintenance Signals
Community Trust
Mailing Group Listserv Alternatives
WP Mailster
wp-mailster
WP Mailster allows your users to be part of a group and communicate by email without having to log into a website.
Participants Database
participants-database
Build and maintain a fully customizable database of participants, members or anything with signup forms, admin backend, custom lists, and CSV support.
Newsletters
newsletters-lite
Newsletter plugin for WordPress to capture subscribers and send beautiful, bulk newsletter emails.
Benchmark Email Lite
benchmark-email-lite
Your Wordpress Site and Email Marketing all in one place!
Contact Form 7 GetResponse Extension
contact-form-7-getresponse-extension
A very easy plugin to integrate GetResponse campaigns with Contact Form 7.
Mailing Group Listserv Developer Profile
1 plugin · 100 total installs
How We Detect Mailing Group Listserv
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.