Comment Reply Email

Comment Reply Email has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Comment Reply Email has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Comment Reply Email is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Comment Reply Email vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-35773

Comment Reply Email <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Comment Reply Email banner
Latestv1.6.0

Comment Reply Email

treeflips

Author

treeflips

4.7(15)
94/100
Last Updated
2025-06-27 (1y ago)
Active Installs
500+
Downloads
17,387
Requires WP
4.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2020-06-18 (6y ago)

This simple plugin automatically sends a notification email to commenters when someone replies to their comment. This feature can be enabled automatically by the site admin, or through an opt-in/opt-out checkbox below comment section on frontend. It’s best to use it with an email-sending plugin like WP Mail SMTP, and with SMTP or transactional email service like SendGrid or Mailgun. Sending from your server via PHPmailer can cause deliverability issues (email notfications caught in spam). I loved the original plugin Comment Reply Notification (by @denishua) for its simplicity but it was abandoned and stopped working years ago. So I forked and revived it to work with the latest PHP and WordPress. I also improved some wording, removed unnecessary author links in the email notifications, and also keep it more updated. Credits to Denis who first hacked it 5 years ago, and later Walter for fixing string escapes. Features: Feature modes – disabled, author/admin replies only, automatically, checkbox opt-in. Edit email notification – subject and message. [year] shortcode for dynamic year in email templates. Developer-friendly hook for adding custom shortcodes. Fixes issue with email notifications for moderated comments. Can delete plugin options – after deactivation.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C