Emailchef
Emailchef has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Emailchef has a vendor fix available, so running the current release closes it.
All of these findings were reported by Legion Hunter. Emailchef is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-1930Emailchef <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
Read the full analysisVulnerability Records

Emailchef
Author
hanicker
Emailchef Mail Marketing Automation Elevate your email marketing strategy with the Emailchef for WordPress plugin, a dynamic interface that integrates directly with Emailchef.com. Emailchef offers an array of subscription plans, each catering to different levels of functionality and contact management requirements. If your needs are unique, take advantage of a bespoke plan tailored just for you. This plugin is the ideal enhancement for your site, offering a powerful and user-friendly email campaign management system. Connect your website forms seamlessly with Emailchef. Our plugin automatically captures submissions from a variety of form builders—including Elementor, WPForms, Contact Form 7, Fast Secure Contact Form (FSCF), Jetpack, and more (ask us about additional plugin support!). As responses flow in, they’re instantly synchronized with your chosen Emailchef contact list. Further tailor your marketing efforts with support for custom fields, allowing for sophisticated segmentation of your audience. For instance, categorize your subscribers by their roles, such as resellers or hoteliers, and curate newsletters designed specifically for them. With Emailchef for WordPress, you’re equipped to communicate with precision and impact.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C