Emu2 – Email Users 2
Emu2 – Email Users 2 has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Emu2 – Email Users 2 has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. Emu2 – Email Users 2 is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.2.1.
CVE-2025-52750Emu2 <= 0.83b - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Emu2 – Email Users 2
Author
Juergen Schulze
A plugin for wordpress which allows you to send an email to the registered blog users. Users can send personal emails to each other. Power users can email groups of users and even notify group of users of posts. With ability to schedule mails of the newest post in digest form. ! ! ! S T I L L B E T A ! ! ! All the instructions for installation, the support forums, a FAQ, etc. can be found on the plugin home page. This plugin is available under the GPL license, which means that it’s free. But a “thank you” on my blog is highly apprechiated. Check out my other WordPress Plugins Remove plugin Deactivate plugin through the ‘Plugins’ menu in WordPress Delete plugin through the ‘Plugins’ menu in WordPress It’s best to use the build in delete function of wordpress. That way all the stored data will be removed and no orphaned data will stay. To do More translations. Does someone wants to help?
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C