Mailtree Log Mail
Mailtree Log Mail has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Mailtree Log Mail has a vendor fix available, so running the current release closes it.
All of these findings were reported by Alex Thomas. Mailtree Log Mail is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2023-3135Mailtree Log Mail <= 1.0.0 - Unauthenticated Stored Cross-Site Scripting via Email Subject
Read the full analysisVulnerability Records

Mailtree Log Mail
Author
oacstudio
This plugin logs all mails that use the wp_mail() function (should be almost all). Mail can be viewed, downloaded as CSV and resend. The plugin has REST API support. Log entries can also be exported automatically to another (archive) WordPress site that runs Mailtree. Mailtree uses the REST API for exporting entries and also has an automatic retry function to account for connection errors. Feature list Logs: Logs all emails using the wp_mail() function (should be almost all!). Download single entry as CSV. Bulk download entries as CSV. Download all entries as CSV. Delete single entry. Bulk delete entries. View all, only failed or only successful sent messages. Logs additional info such as trigger, exact time, content type, reply to address and full HTML. Search log entries. Settings: Set capability to view logs. Set capability to view settings. Auto export / REST API: Export all entries to an external site automatically using Application Passwords and the REST API. Great for keeping a mail archive. Failed auto exports are retried automatically. Provides two REST API endpoints to save log entries (sent successful / failed). Misc: Translation-Ready Roadmap: Attachements are not logged or saved. However the message detail will show a notification that an attachement was sent.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C