A serious security flaw in the widely used Post SMTP plugin for WordPress directly threatens over 200,000 websites worldwide, giving cybercriminals the ability to gain full access to administrative accounts.

Post SMTP, with over 400,000 active installations, is a key tool for reliably sending emails through WordPress, replacing the core 'wp_mail()' function with a more flexible and stable implementation. However, a critical vulnerability in versions up to 3.2.0 reveals significant weaknesses in access control to the plugin's REST API endpoints.
See also: SonicWall patches critical SMA 100 vulnerability
The vulnerability was reported by a researcher on May 23, recorded with the identifier CVE-2025-24000 , and rated 8.8 out of 10, classifying it as a high severity threat.
How the attack works – From “subscriber” to “administrator” with an email
The issue lies in inadequate rights verification when accessing sensitive endpoints. While it checks whether a user is logged in, it doesn’t check whether they have the appropriate permissions. This allows even users with minimal access – such as “Subscribers” – to read logs email that contain, among other things, password reset emails.
On vulnerable WordPress sites, an attacker can initiate a password reset for the administrator, locate the reset email in the logs, and ultimately gain full control of the site.
The developer 's reaction and the situation today
The creator of the Post SMTP plugin, Saad Iqbal, was notified of the vulnerability and released an update on May 26, incorporating stricter access checks in the get_logs_permission function. The secure version 3.3.0 was released on June 11.
See also: GitLab security update fixes multiple vulnerabilities
However, the delay in users upgrading is a concern. According to WordPress.org, as of yesterday, only 48.5% of installations had switched to the secure version, with over 200,000 sites remaining vulnerable.
Even more worrying is the fact that approximately 96,800 websites (24.2%) continue to run Post SMTP versions from the 2.x branch, which in addition to CVE-2025-24000 also include other security vulnerabilities.

Why is the Post SMTP plugin dangerous for WordPress sites?
This incident highlights a perennial problem in the WordPress ecosystem: widely used plugins become easy targets when software updates are ignored or delayed by site administrators. Plugins specifically related to email and communications management can become a powerful tool in the hands of attackers.
See also: Firefox 141 fixes multiple vulnerabilities
This vulnerability offers a "by-design" scenario for elevation of privilege attacks, where a low-level user can bypass controls and gain critical access in just a few steps.
Recommendations for WordPress administrators :
- Immediately upgrade Post SMTP to version 3.3.0 or later.
- Limit user rights to what is absolutely necessary.
- Use security plugins that log REST API activity.
- Set up notifications for password reset.
- Check for unexplained access to email logs.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
