HomeSecurityPOST SMTP Mailer: Vulnerabilities in WordPress plugin - Update immediately!

POST SMTP Mailer: Vulnerabilities in WordPress plugin – Update immediately!

Two vulnerabilities have been found in the POST SMTP Mailer plugin for WordPress. It is a popular email delivery tool, used by 300,000 websites.

POST SMTP Mailer WordPress plugin

Last month, WordfenceUlysses Saicha and Sean Murphydiscovered the two vulnerabilities and reported them to the vendor.

CVE-2023-6875

The first vulnerability (CVE-2023-6875) is a critical bug resulting from a “type juggling” issue in the connect-app REST endpoint. The issue affects POST SMTP Mailer plugin versions up to version 2.8.7.

Essentially, with this vulnerability, an unauthenticated attacker could reset the API key and view sensitive log information, including emails password reset.

See also: AI Engine: Vulnerability in WordPress plugin puts 50,000 sites at risk

How it works

The attacker can exploit a function in the mobile app to set a valid token with a zero value for the authentication key ,via a request.

It then triggers a password reset for the site administrator and accesses the key within the app. It then changes it and locks the legitimate user out of the account.

The attacker has now gained administrator rights and full access, which allows them to do whatever they want. They can install malware, modify plugins and themes, edit and publish content, redirect users to malicious sites, and more.

CVE-2023-7027

The second vulnerability (CVE-2023-7027), is a cross-site scripting (XSS) issue, resulting from inadequate input sanitization and output escaping.

It affects the POST SMTP Mailer WordPress plugin up to version 2.8.7 and could allow attackers to inject arbitrary scripts into the web pages of the affected site.

Wordfence researchers notified the vendor about the critical flaw on December 8, 2023, and released a proof-of-concept (PoC) exploit on December 15.

See also: Backup Migration: WordPress plugin vulnerable to critical vulnerability

The XSS issue was reported on December 19, 2023, and a PoC was shared the next day.

On January 1, 2024, version 2.8.8 of the POST SMPT plugin was released, which fixes the two vulnerabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Based on wordpress.org statistics, there are approximately 150,000 WordPress sites running a vulnerable version of POST SMPT.

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur. 

POST SMTP Mailer vulnerabilities
POST SMTP Mailer: Vulnerabilities in WordPress plugin – Update immediately!

Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers . If their data is compromised, they’re more likely to sue you and switch to other companies. 

See also: WordPress: POP chain allows RCE attacks – Update immediately!

Securing your website is also important for maintaining the consistency and credibility of your content. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

In other words, ensuring your WordPress website is secure isn’t just about protecting data – it’s about ’ trust customers , preserving your company’s reputation, and staying on top of the competition.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS