WP Mail Logging

WP Mail Logging has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2026; all 7 are fixed as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 2 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 3 of the records (43%). Other recurring categories include Cross-Site Scripting, Cross-Site Request Forgery (CSRF).

Every one of the 7 issues recorded for WP Mail Logging has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, one record each. WP Mail Logging is installed on roughly 300,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.6/ 10
Patch Coverage100%
Open

0

Fixed

7

Get automatic notifications for all WP Mail Logging vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2026-2471

WP Mail Logging <= 1.15.0 - Unauthenticated PHP Object Injection via Email Log Message Field

Read the full analysis

Vulnerability Records

7 records
WP Mail Logging banner
Latestv1.16.0

WP Mail Logging

Syed Balkhi

Author

Syed Balkhi

4.7(367)
94/100
Last Updated
2026-02-19 (7mo ago)
Active Installs
300,000+
Downloads
4,926,306
Requires WP
5.3+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2014-06-13 (12y ago)

WP Mail Logging is the most popular plugin for logging emails sent from your WordPress site. Simply activate it and it will work immediately, no extra configuration is needed. Are your WordPress emails not being sent or delivered? Use this plugin to log all outgoing emails from your WordPress site. If there are any errors when sending the email from your site, our email logs will catch that error and display it to you. This will allow you to debug and fix your email sending issue. Did a client not receive your email? Our email logs allow you to resend any email that was sent from your site. No more lost emails! Do you just want to keep a record of all emails sent from your site? By default, WordPress and your web host do not log, store or keep track of emails sent from your website. This plugin will allow you to do just that. Our email logs will store every email that is sent from your WordPress site. You can search and view a particular email log, inspect its content or attachments, and even resend that email. What email information is logged? All emails sent from your WordPress site are logged. And here is the information that is stored: Email Subject Email Content (HTML or text) Email Attachments Email Headers (to, from, reply-to, cc, bcc, …) Error Message (in case there was an error while attempting to send the email) IP Address of originating server (can be enabled in the settings) Date and Time of the email Receiver (the TO email address) Why are my logged emails still not delivered to the inbox? There are a lot of steps that emails have to make in order to be delivered to the recipient’s inbox. When your WordPress site sends an email, there’s no guarantee it will be delivered. This is what the email’s journey looks like: WordPress creates an email WordPress passes the email to your website host and that email gets logged by our plugin The host server takes the email and sends it (SMTP or Mail Transfer Agent) Recipient server receives or blocks the email If the email is accepted, the spam filter decides if it goes to the inbox or the spam folder Recipients see the email and might open it. This plugin does not track delivery after step 2. If you have deliverability issues, we suggest installing the WP Mail SMTP plugin. WP Mail SMTP fixes WordPress email deliverability problems, you can choose between 12 email providers (Gmail, Outlook, SendLayer, Mailgun, …) to resolve your email sending issue and it’s super easy to set up. WP Mail SMTP is trusted by more than 3 million websites. Credits The plugin was created and launched in 2014 by Christian Zöller.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C