Plugin Vulnerability Hub
Plugin 23 known issues Latest disclosed Mar 17, 2026

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Vulnerabilities

Review known vulnerability records for the WordPress plugin Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App (`post-smtp`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-3090, CVE-2026-2559 and CVE-2025-12887, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
23
High or Critical
11
Patch Coverage
100%
Last Updated
Mar 18, 2026
Priority CVE Quick Links

Fast paths into Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
22
CVE-2025-11833 Critical 3.6.1
CVE-2025-11833 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Vulnerability

Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure

CVE-2023-6875 Critical 2.8.8
CVE-2023-6875 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Authorization Bypass

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API

CVE-2025-24000 High 3.3.0
CVE-2025-24000 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Privilege Escalation

Post SMTP <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via Email Log Exposure

CVE-2026-3090 High 3.9.0
CVE-2026-3090 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Stored Cross-Site Scripting

Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'

CVE-2025-0521 High 3.1.0
CVE-2025-0521 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Stored Cross-Site Scripting

Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-5207 High 2.9.4
CVE-2024-5207 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App SQL Injection

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection

CVE-2023-7027 High 2.8.8
CVE-2023-7027 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Stored Cross-Site Scripting

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device

CVE-2023-6620 High 2.8.7
CVE-2023-6620 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App SQL Injection

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.6 - Authenticated (Administrator+) SQL Injection

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
23 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 9 high severity findings.
Recent CVEs
CVE-2026-3090, CVE-2026-2559 and CVE-2025-12887
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-3090
CVE-2026-3090: Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input...

Published
Mar 17, 2026
Patched Release
3.9.0
Affected Versions
Versions up to 3.8.0
Next Step
Update to 3.9.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2559
CVE-2026-2559: Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` withou...

Published
Mar 17, 2026
Patched Release
3.9.0
Affected Versions
Versions up to 3.8.0
Next Step
Update to 3.9.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12887
CVE-2025-12887: Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it pos...

Published
Dec 03, 2025
Patched Release
3.6.2
Affected Versions
Versions up to 3.6.1
Next Step
Update to 3.6.2 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-11833
CVE-2025-11833: Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible f...

Published
Oct 31, 2025
Patched Release
3.6.1
Affected Versions
Versions up to 3.6.0
Next Step
Update to 3.6.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9219
CVE-2025-9219: Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update

The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_post_smtp...

Published
Sep 02, 2025
Patched Release
3.4.2
Affected Versions
Versions up to 3.4.1
Next Step
Update to 3.4.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-24000
CVE-2025-24000: Post SMTP <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via Email Log Exposure

The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable privilege escalation via account takeover due to a missing capability check on the get_details(...

Published
Jul 21, 2025
Patched Release
3.3.0
Affected Versions
Versions up to 3.2.0
Next Step
Update to 3.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13844
CVE-2024-13844: Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter

The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...

Published
Mar 07, 2025
Patched Release
3.1.3
Affected Versions
Versions up to 3.1.2
Next Step
Update to 3.1.3 or newer if supported.
Plugin High Patched: Yes CVE-2025-0521
CVE-2025-0521: Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...

Published
Feb 17, 2025
Patched Release
3.1.0
Affected Versions
Versions up to 3.0.2
Next Step
Update to 3.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-22800
CVE-2025-22800: Post SMTP <= 2.9.11 - Missing Authorization via regenerate_qrcode()

The Post SMTP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the regenerate_qrcode() function in versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to g...

Published
Jan 07, 2025
Patched Release
2.9.12
Affected Versions
Versions up to 2.9.11
Next Step
Update to 2.9.12 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-52436
CVE-2024-52436: Post SMTP <= 2.9.9 - Authenticated (Administrator+) SQL Injection

The Post SMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,...

Published
Nov 15, 2024
Patched Release
2.9.10
Affected Versions
Versions up to 2.9.9
Next Step
Update to 2.9.10 or newer if supported.
Plugin High Patched: Yes CVE-2024-5207
CVE-2024-5207: POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection

The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insufficient escaping on the us...

Published
May 22, 2024
Patched Release
2.9.4
Affected Versions
Versions up to 2.9.3
Next Step
Update to 2.9.4 or newer if supported.
Plugin Critical Patched: Yes CVE-2023-6875
CVE-2023-6875: POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and in...

Published
Jan 10, 2024
Patched Release
2.8.8
Affected Versions
Versions up to 2.8.7
Next Step
Update to 2.8.8 or newer if supported.