← WordPress Vulnerabilities
WordPress security by component

Post SMTP

Post SMTP is a WordPress component with 27 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: post-smtp

CVE-2026-48838: Post SMTP: Cross-site scripting

Post SMTP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.6.2.

PublishedJun 15, 2026
Known safe version3.6.3
Safe version
Jun 15, 2026 CVE-2026-48838
Post SMTP: Cross-site scripting
Post SMTP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.6.2.
3.6.3
CVE7.1
NVDPending
Mar 18, 2026 CVE-2026-3090
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App: Cross-site scripting
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Mar 18, 2026 CVE-2026-2559
Post SMTP: A security weakness
Post SMTP is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 09, 2025 CVE-2025-67563
Post SMTP: A security weakness
Post SMTP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 03, 2025 CVE-2025-12887
Post SMTP: A security weakness
Post SMTP is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Nov 01, 2025 CVE-2025-11833
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App: Privilege escalation or authentication bypass
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Sep 03, 2025 CVE-2025-9219
Post Smtp: A security weakness
Post Smtp is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 07, 2025 CVE-2025-24000
Post SMTP: Privilege escalation or authentication bypass
Post SMTP is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Mar 08, 2025 CVE-2024-13844
Post SMTP: SQL injection
Post SMTP is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVD4.9
Feb 18, 2025 CVE-2025-0521
Post SMTP: Cross-site scripting
Post SMTP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jan 13, 2025 CVE-2025-22800
Post SMTP: A security weakness
Post SMTP is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Nov 18, 2024 CVE-2024-52436
Post SMTP: SQL injection
Post SMTP is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Jun 11, 2024 CVE-2023-52233
Post SMTP Mailer/Email Log: A security weakness
Post SMTP Mailer/Email Log is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.6
NVD9.8
May 30, 2024 CVE-2024-5207
#1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications: SQL injection
#1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Mar 19, 2024 CVE-2024-29128
POST SMTP: Cross-site scripting
POST SMTP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jan 16, 2024 CVE-2023-3178
POST SMTP Mailer: Cross-site request forgery
POST SMTP Mailer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jan 15, 2024 CVE-2023-6620
POST SMTP Mailer: SQL injection
POST SMTP Mailer is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Jan 11, 2024 CVE-2023-6875
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for: A security weakness
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jan 03, 2024 CVE-2023-6621
POST SMTP: Cross-site scripting
POST SMTP is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 03, 2024 CVE-2023-7027
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for: Cross-site scripting
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD5.4
Jan 03, 2024 CVE-2023-6629
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for: Cross-site scripting
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Nov 27, 2023 CVE-2023-5958
POST SMTP Mailer: Cross-site scripting
POST SMTP Mailer is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 17, 2023 CVE-2023-3179
POST SMTP Mailer: Cross-site request forgery
POST SMTP Mailer is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Jul 12, 2023 CVE-2021-4422
POST SMTP Mailer: Cross-site request forgery
POST SMTP Mailer is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jul 12, 2023 CVE-2023-3082
Post SMTP: Cross-site scripting
Post SMTP is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Sep 26, 2022 CVE-2022-2352
Post SMTP Mailer/Email Log: Server-side request forgery
Post SMTP Mailer/Email Log is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.2
NVD7.2
Sep 16, 2022 CVE-2022-2351
Post SMTP Mailer/Email Log: Cross-site scripting
Post SMTP Mailer/Email Log is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8