Elastic Email Sender

Elastic Email Sender has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Elastic Email Sender has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Elastic Email Sender is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Elastic Email Sender vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-38387

Elastic Email Sender <= 1.2.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Elastic Email Sender banner
Latestv1.2.22

Elastic Email Sender

Elastic Email

Author

Elastic Email

4.8(10)
96/100
Last Updated
2025-12-03 (9mo ago)
Active Installs
10,000+
Downloads
293,141
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2017-06-16 (9y ago)

Elastic Email Sender allows you to connect your WordPress with our powerful, low-cost Elastic Email API and start sending marketing or transactional emails! Please follow the information below and find out more about how we can help you send your emails in a more efficient way. In case of any questions or concerns, feel free to contact us anytime. What is the Elastic Email Sender plugin? The Elastic Email Sender plugin is an easy way to maintain all the aspects related to your email campaigns. From creating and sending your emails to monitoring and managing campaign stats. Elastic Email Sender replaces the WordPress default wp_mail() function by using API integration with Elastic Email to send an outgoing email from your WordPress installation. Thanks to this, you can track all the parameters of your delivery, use Private IP addresses to get full control over your sending, maintain reputation and delivery and secure your data better than ever. You can also use your own domain and analyze your data with ease. Elastic Email Sender is compatible with almost every solution available on the market including WooCommerce, Contact Form 7, Ninja Forms, Flamingo, Caldera Forms, bbPress How to get started? Just sign into your Elastic Email account, copy the API Key. Next, please login to your WordPress dashboard, add the Elastic Email Sender plugin and paste there the API Key from your Elastic Email account. Translations You can translate Elastic Email Sender on translate.wordpress.org.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C