Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

Information

Software Type Plugin
Software Slug post-smtp (view on wordpress.org)
Software Status Active
Software Author saadiqbal
Software Website postmansmtp.com
Software Downloads 19,802,844
Software Active Installs 300,000
Software Record Last Updated July 21, 2026

Showing 1-20 of 26 Vulnerabilities

7.2
CVE ID Unknown
Oct 3, 2023
Researchers:
Title Status CVE ID CVSS Researchers Date
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App <= 3.6.2 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-48838 7.2 Drew Webber (mcdruid) May 28, 2026
Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter Patched CVE-2024-13362 6.1 Asaf Mozes April 30, 2026
Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' Patched CVE-2026-3090 7.2 h0xilo March 17, 2026
Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite Patched CVE-2026-2559 5.3 Michael Iden (Mickhat) March 17, 2026
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update Patched CVE-2025-12887 5.4 type5afe December 3, 2025
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure Patched CVE-2025-11833 9.8 netranger October 31, 2025
Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update Patched CVE-2025-9219 4.3 Matteo Leonelli, David D. September 2, 2025
Post SMTP <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via Email Log Exposure Patched CVE-2025-24000 8.8 Denver Jackson July 21, 2025
Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter Patched CVE-2024-13844 4.9 Nhien Pham (nhienit) March 7, 2025
Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2025-0521 7.2 zer0gh0st February 17, 2025
Post SMTP <= 2.9.11 - Missing Authorization via regenerate_qrcode() Patched CVE-2025-22800 4.3 Rafie Muhammad January 7, 2025
Post SMTP <= 2.9.9 - Authenticated (Administrator+) SQL Injection Patched CVE-2024-52436 4.9 Hakiduck November 15, 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection Patched CVE-2024-5207 7.2 Le Ngoc Anh May 22, 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API Patched CVE-2023-6875 9.8 Ulyses Saicha January 10, 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device Patched CVE-2023-7027 7.2 Sean Murphy January 2, 2024
POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg Patched CVE-2023-6629 6.1 Matan Berson (matanber) January 2, 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.6 - Authenticated (Administrator+) SQL Injection Patched CVE-2023-6620 7.2 Alex Sanford December 21, 2023
POST SMTP Mailer <= 2.7.0 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2023-5958 7.2 Marcin Węgłowski November 6, 2023
Post SMTP <= 2.6.0 - Authenticated (Administrator+) SQL Injection Patched 7.2 October 3, 2023
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get Patched CVE-2023-33999 6.1 Rafie Muhammad July 18, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation