Elastic Email Sender
Elastic Email Sender has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Elastic Email Sender has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Elastic Email Sender is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2023-38387Elastic Email Sender <= 1.2.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Elastic Email Sender
Author
Elastic Email
Elastic Email Sender allows you to connect your WordPress with our powerful, low-cost Elastic Email API and start sending marketing or transactional emails! Please follow the information below and find out more about how we can help you send your emails in a more efficient way. In case of any questions or concerns, feel free to contact us anytime. What is the Elastic Email Sender plugin? The Elastic Email Sender plugin is an easy way to maintain all the aspects related to your email campaigns. From creating and sending your emails to monitoring and managing campaign stats. Elastic Email Sender replaces the WordPress default wp_mail() function by using API integration with Elastic Email to send an outgoing email from your WordPress installation. Thanks to this, you can track all the parameters of your delivery, use Private IP addresses to get full control over your sending, maintain reputation and delivery and secure your data better than ever. You can also use your own domain and analyze your data with ease. Elastic Email Sender is compatible with almost every solution available on the market including WooCommerce, Contact Form 7, Ninja Forms, Flamingo, Caldera Forms, bbPress How to get started? Just sign into your Elastic Email account, copy the API Key. Next, please login to your WordPress dashboard, add the Elastic Email Sender plugin and paste there the API Key from your Elastic Email account. Translations You can translate Elastic Email Sender on translate.wordpress.org.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C