Emu2 – Email Users 2

Emu2 – Email Users 2 has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Emu2 – Email Users 2 has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Nguyen Xuan Chien. Emu2 – Email Users 2 is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.2.1.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Emu2 – Email Users 2 vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2025-52750

Emu2 <= 0.83b - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv0.83b

Emu2 – Email Users 2

Juergen Schulze

Author

Juergen Schulze

4.0(1)
80/100
Last Updated
2011-11-23 (15y ago)
Active Installs
80+
Downloads
20,298
Requires WP
2.8+
Requires PHP
0+
Tested up to
WP 3.2.1
Created
2011-01-10 (16y ago)

A plugin for wordpress which allows you to send an email to the registered blog users. Users can send personal emails to each other. Power users can email groups of users and even notify group of users of posts. With ability to schedule mails of the newest post in digest form. ! ! ! S T I L L B E T A ! ! ! All the instructions for installation, the support forums, a FAQ, etc. can be found on the plugin home page. This plugin is available under the GPL license, which means that it’s free. But a “thank you” on my blog is highly apprechiated. Check out my other WordPress Plugins Remove plugin Deactivate plugin through the &#8216;Plugins’ menu in WordPress Delete plugin through the &#8216;Plugins’ menu in WordPress It’s best to use the build in delete function of wordpress. That way all the stored data will be removed and no orphaned data will stay. To do More translations. Does someone wants to help?

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C