CVE-2025-49288: WordPress Ultimate WP Mail plugin <= 1.3.5 - Account Takeover via Email Log Leak Vulnerability
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate WP Mail: from n/a through 1.3.5.
Other sources
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This issue affects Ultimate WP Mail: from n/a through <= 1.3.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49288?
CVE-2025-49288 is classified as a Missing Authorization vulnerability that can significantly impact the security of affected systems.
How do I fix CVE-2025-49288?
To fix CVE-2025-49288, update the Rustaurius Ultimate WP Mail plugin to the latest version that addresses the access control issues.
What versions of Ultimate WP Mail are affected by CVE-2025-49288?
CVE-2025-49288 affects all versions of Rustaurius Ultimate WP Mail up to and including version 1.3.5.
What type of attack can exploit CVE-2025-49288?
CVE-2025-49288 can be exploited by attackers to bypass authorization controls and potentially gain unauthorized access to sensitive information.
Is there a known workaround for CVE-2025-49288?
Currently, the recommended approach to mitigate CVE-2025-49288 is to upgrade to a patched version of the plugin.