WP Change Email Sender
WP Change Email Sender has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for WP Change Email Sender has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dhabaleshwar Das. WP Change Email Sender is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-29815WP Change Email Sender <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP Change Email Sender
Author
Md Aminur Islam
This plugin enable you to change mail sender name and email address from WordPress default mail sender name and email. After installation, navigate to Settings → Change Email Sender in the WordPress admin sidebar to open the modern configuration dashboard. Plugin Features ✉️ Custom Sender Details: Easily replace the default “WordPress” name and “wordpress@yourdomain.com” email address with your own brand. 🛡️ Force Overrides: Prevent misbehaving plugins (e.g., contact forms or e-commerce plugins) from hijacking your outbound email sender details. ↩️ Smart “Reply-To” Protection: When forcing an email override, the plugin automatically captures the original sender and sets it as the “Reply-To” address so you never miss a customer reply. 🧪 Built-in Email Tester: Instantly send a test email directly from the settings page to verify your configuration is working perfectly. 💾 Import & Export: Securely back up your custom configurations to a JSON file or restore them instantly with the built-in drag-and-drop uploader. ⚡ Lightning Fast Dashboard: Enjoy a stunning, single-page React interface that saves your settings instantly without page reloads. 🔒 Lightweight & Secure: Built with the native WordPress REST API and rigorous security standards. Support If you find this plugin useful, consider supporting its development through a donation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C