wordpress publish post email notification

wordpress publish post email notification has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for wordpress publish post email notification has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. wordpress publish post email notification is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all wordpress publish post email notification vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-41731

wordpress publish post email notification <= 1.0.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.0.2.4

Publish Post Email Notification

Nks

Author

Nks

5.0(3)
100/100
Last Updated
2026-08-03 (1mo ago)
Active Installs
600+
Downloads
19,484
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2012-08-29 (14y ago)

Automatically email the post author when their content is published and approved by the admin — set it up once, no coding needed. Pro version adds custom post type support. Find WP publish post email notification Pro Plugin at Publish Post Email Notification Pro =Features= set email template. Notify author via email when post is published. =Pro Version Features= 1.Support for send email to author when custom post type published 2.No Advertisements. Get Support License This plugin is free for everyone! Since it’s released under the GPL, you can use it free of charge on your personal or commercial blog. But you can make some donations if you realy find it useful.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C