Fatal Error Notify
Fatal Error Notify has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for Fatal Error Notify has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Dmitrii Ignatyev. Fatal Error Notify is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
Fatal Error Notify <= 1.5.2 - Cross-Site Request Forgery to Test Error Email Sending
Read the full analysisVulnerability Records

Fatal Error Notify
Author
Jack Arturo
This plugin sends you an email notification whenever a fatal error (or other error level, configurably) is detected on your site. Unlike traditional uptime monitoring services, which will only notify you if your entire site is down, this plugin can notify you when an error is detected on any page or process on your site. Automatic plugin and theme updates often introduce problems that you aren’t aware of until they’re reported by your visitors. Fatal Error Notify lets you address these issues as they occur and before they cause significant problems.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C