HomeSecurityVulnerability in WordPress Post SMTP plugin - 400,000 sites at risk 

Vulnerability in WordPress Post SMTP plugin – 400,000 sites at risk 

A serious security flaw in the popular WordPress Post SMTP plugin leaves more than 400,000 websites exposed to account takeover attacks. The vulnerability, listed as CVE-2025-11833, results from a lack of authorization checks at the point where email logs are handled, allowing unauthorized attackers to read stored messages, including password reset links.

WordPress Post SMTP plugin

What exactly is happening?

The vulnerable code is located in the PostmanEmailLogs class constructor, which displays logged email messages without performing capability checks in the __construct function. Attackers can manipulate URL parameters (e.g. page, view, log_id) to retrieve arbitrary log files from the database and gain access to password reset links. This scenario allows a two-pronged attack: generating a reset request and reading the corresponding email to take over the account.

See also: CISA adds Gladinet and CWP vulnerabilities to KEV List

Troubleshooting and patching

The WP Experts development team has released version 3.6.1 to close the gap; the patch was released on October 29, 2025, and affects all versions up to 3.6.0. Administrators are urged to update immediately, as the bug has a CVSS score of 9.8 — meaning it is “critical” and poses an immediate risk to WordPress sites.

Who discovered it and what is the scope of the exploitation?

The vulnerability in the WordPress Post SMTP plugin was discovered and responsibly reported by security researcher netranger through a bug bounty program; a reward of $7,800 was awarded for the find. Active exploitation attempts — thousands of requests have already been blocked by security systems, while reports indicate ongoing malicious activity.

Vulnerability in WordPress Post SMTP plugin - 400,000 sites at risk 

What risks does this error pose for websites?

The ability to read logged emails means an attacker can bypass authentication processes and gain administrator privileges without additional access. With full privileges, the attacker can install backdoors, modify content, create malicious redirects, or steal user data — impacts that translate into loss of trust, financial damage, and compliance issues.

See also: Vulnerability in React Native CLI puts millions of developers at risk

Recommendations for administrators

Update the Post SMTP plugin to version 3.6.1. Additionally, check your logs for suspicious password resets and detect new or unknown administrators. Implement good security practices: strong, unique passwords, MFA for all accounts with administrator privileges, and restrict access to the admin environment with IP whitelisting where possible. Application security systems and WAFs already have relevant rules in place to mitigate attacks.

Technical attack diagram

The vector is simple: the attacker triggers a password reset for a target account and requests the corresponding log_id via the unprotected interface. If the reset email is retrieved, the link allows a password change and full access to the site — a scenario that leads to the placement of backdoors or redirection of visitors.

Cooperation and defense

Bug bounty discovery and rapid patching demonstrate effective collaboration between researchers and developers, but many sites are lagging behind in upgrading. As interim measures, we recommend disabling email logging, checking logs for suspicious resets, implementing MFA, and restricting access to wp-admin.

See also: Warning! Serious vulnerabilities in Microsoft Teams

Vulnerability in WordPress Post SMTP plugin - 400,000 sites at risk 

Tracking and monitoring

Use web application security (WAF) tools and entry point scanning plugins, enable alerts for abnormal password resets , and check recent user changes. Also, review database permissions and limit logging of sensitive data.

The case is a reminder that even “support” functions like email logs are a significant attack surface when permissions checks are lacking. Prompt notification and proactive monitoring are critical.

Attention to safety must be constant.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS