Easy Voice Mail

Easy Voice Mail has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Easy Voice Mail has a vendor fix available, so running the current release closes it.

All of these findings were reported by Kazuma Matsumoto. Easy Voice Mail is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Easy Voice Mail vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2026-1164

Easy Voice Mail <= 1.2.5 - Unauthenticated Stored Cross-Site Scripting via 'message'

Read the full analysis

Vulnerability Records

1 records
Easy Voice Mail banner
Latestv1.2.6

Easy Voice Mail

Phoenix Studio

Author

Phoenix Studio

5.0(4)
100/100
Last Updated
2026-02-23 (7mo ago)
Active Installs
100+
Downloads
5,617
Requires WP
6.2+
Requires PHP
5.6.20+
Tested up to
WP 6.9.7
Created
2020-05-02 (7y ago)

Easy Voice mail Provides a simpler, more efficient way for your clients to contact you and express their needs via voice mail. This plugin provides an easy way to enable your clients to contact you by sending you a voice mail, all they will need to do is to hit the record button and save the message once they are done. * The plugin provides a clean and comfortable user interface to review and manage the voice messages. * The plugin provides a configuration panel that enables you to limit the message duration and set a custom message for users, displayed in the clients side. * The plugin will enable (request using) microphone only during recording. * Easy to install and set, 2 steps only, no registration, SignUp or third party services are required. * We care about privacy, all messages are stored in the website, the plugin does not use any third party for storage or library that can track you or your clients. * Works on most current desktop and mobile web browsers. * Direct links to download recoreded files to computer or phone. * Notification by email. Important: Due to security limitations, the web browser will not allow the usage of the microphone in non-https connection, which means that the plugin will only work on websites where https connection is enabled.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C