← WordPress Vulnerabilities
WordPress security by component

SureMail – SMTP and Email Logs

SureMail – SMTP and Email Logs is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Dec 02, 2025; the highest CVE/CNA score is 8.1.

Plugin slug: suremails

CVE-2025-13516: SureMail – SMTP and Email Logs: Dangerous file upload

SureMail – SMTP and Email Logs is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.

PublishedDec 02, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 02, 2025 CVE-2025-13516
SureMail – SMTP and Email Logs: Dangerous file upload
SureMail – SMTP and Email Logs is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.1
NVDPending