Medium 6.5
2025-09-22< 1.3.9
Ultimate WP Mail <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Minimum safe version
1.3.9
Update to 1.3.9 or later to address 5 fixable vulnerabilities
Ultimate WP Mail <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ultimate WP Mail 1.0.17 - 1.3.6 - Missing Authorization to Authenticated (Contributor+) Privilege Escalation via get_email_log_details Function
CVE-2025-49288
CVE-2025-47490
CVE-2025-47466
WordPress Ultimate WP Mail plugin <= 1.3.10 - Open Redirection vulnerability