Easy Voice Mail
Easy Voice Mail has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Easy Voice Mail has a vendor fix available, so running the current release closes it.
All of these findings were reported by Kazuma Matsumoto. Easy Voice Mail is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-1164Easy Voice Mail <= 1.2.5 - Unauthenticated Stored Cross-Site Scripting via 'message'
Read the full analysisVulnerability Records

Easy Voice Mail
Author
Phoenix Studio
Easy Voice mail Provides a simpler, more efficient way for your clients to contact you and express their needs via voice mail. This plugin provides an easy way to enable your clients to contact you by sending you a voice mail, all they will need to do is to hit the record button and save the message once they are done. * The plugin provides a clean and comfortable user interface to review and manage the voice messages. * The plugin provides a configuration panel that enables you to limit the message duration and set a custom message for users, displayed in the clients side. * The plugin will enable (request using) microphone only during recording. * Easy to install and set, 2 steps only, no registration, SignUp or third party services are required. * We care about privacy, all messages are stored in the website, the plugin does not use any third party for storage or library that can track you or your clients. * Works on most current desktop and mobile web browsers. * Direct links to download recoreded files to computer or phone. * Notification by email. Important: Due to security limitations, the web browser will not allow the usage of the microphone in non-https connection, which means that the plugin will only work on websites where https connection is enabled.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C