Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App <= 3.6.2 - Unauthenticated Stored Cross-Site Scripting
high
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 7.2
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.3
- Disclosed:
- May 28, 2026
CVE-2026-48838 on NVD →
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 3.0.0
- Fixed in:
- 3.1.0
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
Post SMTP - Unauthenticated Stored Cross-Site Scripting via 'event_type' vulnerability
high
Unauthenticated Stored Cross-Site Scripting via 'event_type' vulnerability
- CVSS:
- 7.1
- Affected:
- up to 3.8.0
- Fixed in:
- 3.9.0
- Disclosed:
- Mar 20, 2026
Post SMTP - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite vulnerability
medium
Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite vulnerability
- CVSS:
- 5.4
- Affected:
- up to 3.8.0
- Fixed in:
- 3.9.0
- Disclosed:
- Mar 19, 2026
Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'
high
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 7.2
- Affected:
- up to 3.8.0
- Fixed in:
- 3.9.0
- Disclosed:
- Mar 17, 2026
CVE-2026-3090 on NVD →
Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite
medium
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonc...
- CVSS:
- 5.3
- Affected:
- up to 3.8.0
- Fixed in:
- 3.9.0
- Disclosed:
- Mar 17, 2026
CVE-2026-2559 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] <= 3.6.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 3.6.1.
- Affected:
- up to 3.6.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67563 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update
medium
The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it possible for authenticated attackers, with...
- CVSS:
- 5.4
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- Dec 3, 2025
CVE-2025-12887 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2
unknown
[en] The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it possible for authenticated attackers,...
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.2
- Disclosed:
- Dec 3, 2025
CVE-2025-12887 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1
unknown
[en] The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to rea...
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Nov 1, 2025
CVE-2025-11833 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
critical
The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to read arb...
- CVSS:
- 9.8
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.1
- Disclosed:
- Oct 31, 2025
CVE-2025-11833 on NVD →
Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update
medium
The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_post_smtp_pro_option_callback' function in all ve...
- CVSS:
- 4.3
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Sep 2, 2025
CVE-2025-9219 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass.This issue affects Post SMTP: from n/a through 3.2.0.
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Aug 7, 2025
CVE-2025-24000 on NVD →
Post SMTP <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via Email Log Exposure
high
The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable privilege escalation via account takeover due to a missing capability check on the get_details() function in all versions up to, and in...
- CVSS:
- 8.8
- Affected:
- up to 3.2.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jul 21, 2025
CVE-2025-24000 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.3
unknown
[en] The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Mar 8, 2025
CVE-2024-13844 on NVD →
Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter
medium
The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,...
- CVSS:
- 4.9
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Mar 7, 2025
CVE-2024-13844 on NVD →
Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting
high
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...
- CVSS:
- 7.2
- Affected:
- up to 3.0.2
- Fixed in:
- 3.1.0
- Disclosed:
- Feb 17, 2025
CVE-2025-0521 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.12
unknown
[en] Missing Authorization vulnerability in Post SMTP Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through 2.9.11.
- Affected:
- up to 2.9.12
- Fixed in:
- 2.9.12
- Disclosed:
- Jan 13, 2025
CVE-2025-22800 on NVD →
Post SMTP <= 2.9.11 - Missing Authorization via regenerate_qrcode()
medium
The Post SMTP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the regenerate_qrcode() function in versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate QR codes.
- CVSS:
- 4.3
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.12
- Disclosed:
- Jan 7, 2025
CVE-2025-22800 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.10
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9.
- Affected:
- up to 2.9.10
- Fixed in:
- 2.9.10
- Disclosed:
- Nov 18, 2024
CVE-2024-52436 on NVD →
Post SMTP <= 2.9.9 - Authenticated (Administrator+) SQL Injection
medium
The Post SMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and abo...
- CVSS:
- 4.9
- Affected:
- up to 2.9.9
- Fixed in:
- 2.9.10
- Disclosed:
- Nov 15, 2024
CVE-2024-52436 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7
unknown
[en] Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Jun 11, 2024
CVE-2023-52233 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.4
unknown
[en] The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insufficient escaping on the user supplied parameter and lack of s...
- Affected:
- up to 2.9.4
- Fixed in:
- 2.9.4
- Disclosed:
- May 30, 2024
CVE-2024-5207 on NVD →
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection
high
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insufficient escaping on the user supplied parameter and lack of suffic...
- CVSS:
- 7.2
- Affected:
- up to 2.9.3
- Fixed in:
- 2.9.4
- Disclosed:
- May 22, 2024
CVE-2024-5207 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This issue affects POST SMTP: from n/a through 2.8.6.
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Mar 19, 2024
CVE-2024-29128 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7
unknown
[en] The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.
- Affected:
- up to 2.5.7
- Fixed in:
- 2.5.7
- Disclosed:
- Jan 16, 2024
CVE-2023-3178 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7
unknown
[en] The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Jan 15, 2024
CVE-2023-6620 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8
unknown
[en] The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possi...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 11, 2024
CVE-2023-6875 on NVD →
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
critical
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible f...
- CVSS:
- 9.8
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 10, 2024
CVE-2023-6875 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7
unknown
[en] The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possib...
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Jan 3, 2024
CVE-2023-6629 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8
unknown
[en] The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible...
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 3, 2024
CVE-2023-7027 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7
unknown
[en] The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.7
- Disclosed:
- Jan 3, 2024
CVE-2023-6621 on NVD →
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device
high
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for u...
- CVSS:
- 7.2
- Affected:
- up to 2.8.7
- Fixed in:
- 2.8.8
- Disclosed:
- Jan 2, 2024
CVE-2023-7027 on NVD →
POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg
medium
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 6.1
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Jan 2, 2024
CVE-2023-6629 on NVD →
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.6 - Authenticated (Administrator+) SQL Injection
high
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.8.6 due to insufficient escaping on the user supplied parameter and lack of suffic...
- CVSS:
- 7.2
- Affected:
- up to 2.8.6
- Fixed in:
- 2.8.7
- Disclosed:
- Dec 21, 2023
CVE-2023-6620 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.7.1
unknown
[en] The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.1
- Disclosed:
- Nov 27, 2023
CVE-2023-5958 on NVD →
POST SMTP Mailer <= 2.7.0 - Unauthenticated Stored Cross-Site Scripting
high
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email message content in all versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 7.2
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.1
- Disclosed:
- Nov 6, 2023
CVE-2023-5958 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1
unknown
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.6.1).
WordFence discovered and reported this SQL Injection vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to directly interact with your database, including but not limite...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Oct 4, 2023
Post SMTP <= 2.6.0 - Authenticated (Administrator+) SQL Injection
high
The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...
- CVSS:
- 7.2
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Oct 3, 2023
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1
unknown
The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Oct 3, 2023
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 2.1.2-beta.1 – 2.5.7
- Fixed in:
- 2.5.9-beta.1
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7
unknown
[en] The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled...
- Affected:
- up to 2.5.7
- Fixed in:
- 2.5.7
- Disclosed:
- Jul 17, 2023
CVE-2023-3179 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8
unknown
[en] The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute when...
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
- Disclosed:
- Jul 12, 2023
CVE-2023-3082 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21
unknown
[en] The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request g...
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
- Disclosed:
- Jul 12, 2023
CVE-2021-4422 on NVD →
Post SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via Email
high
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever...
- CVSS:
- 7.2
- Affected:
- up to 2.5.7
- Fixed in:
- 2.5.8
- Disclosed:
- Jul 11, 2023
CVE-2023-3082 on NVD →
POST SMTP Mailer <= 2.5.6 - Cross-Site Request Forgery to Account Compromise
medium
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. This is due to incorrect nonce validation on the resend_email() function. This makes it possible for unauthenticated attackers to resend emails to an arbitrary email address via a forged reques...
- CVSS:
- 6.5
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.7
- Disclosed:
- Jun 26, 2023
CVE-2023-3179 on NVD →
POST SMTP Mailer <= 2.5.6 - Cross-Site Request Forgery to Arbitrary Log Deletion
medium
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. This is due to incorrect nonce validation on the delete_logs_ajax() function. This makes it possible for unauthenticated attackers to delete logs granted they can trick a site user with the man...
- CVSS:
- 4.3
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.7
- Disclosed:
- Jun 26, 2023
CVE-2023-3178 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21
unknown
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.7
unknown
[en] The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Sep 26, 2022
CVE-2022-2352 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.4
unknown
[en] The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Sep 16, 2022
CVE-2022-2351 on NVD →
Post SMTP <= 2.1.6 - Authenticated (Administrator+) Blind Server-Side Request Forgery
medium
The Post SMTP plugin for WordPress is vulnerable to blind Server-Side Request Forgery. This is due to improper authorization on some of the plugin's AJAX actions.
- CVSS:
- 6.6
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Sep 5, 2022
CVE-2022-2352 on NVD →
Post SMTP Mailer/Email Log <= 2.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Post SMTP Mailer/Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input_tmp_dir’ parameter in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 5.5
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.4
- Disclosed:
- Aug 18, 2022
CVE-2022-2351 on NVD →
POST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery Bypass
medium
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 2.0.20
- Fixed in:
- 2.0.21
- Disclosed:
- Mar 1, 2021
CVE-2021-4422 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21
unknown
Cross-Site Request Forgery (CSRF) nonce validation vulnerability found in WordPress Post SMTP Mailer/Email Log plugin (versions <= 2.0.20).
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
- Disclosed:
- Feb 11, 2021
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.5.8
- Fixed in:
- 2.5.8
CVE-2023-33999 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0
unknown
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
CVE-2025-0521 on NVD →
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1
unknown
The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1