A serious security flaw in the popular WordPress Post SMTP plugin leaves more than 400,000 websites exposed to account takeover attacks. The vulnerability, listed as CVE-2025-11833, results from a lack of authorization checks at the point where email logs are handled, allowing unauthorized attackers to read stored messages, including password reset links.

What exactly is happening?
The vulnerable code is located in the PostmanEmailLogs class constructor, which displays logged email messages without performing capability checks in the __construct function. Attackers can manipulate URL parameters (e.g. page, view, log_id) to retrieve arbitrary log files from the database and gain access to password reset links. This scenario allows a two-pronged attack: generating a reset request and reading the corresponding email to take over the account.
See also: CISA adds Gladinet and CWP vulnerabilities to KEV List
Troubleshooting and patching
The WP Experts development team has released version 3.6.1 to close the gap; the patch was released on October 29, 2025, and affects all versions up to 3.6.0. Administrators are urged to update immediately, as the bug has a CVSS score of 9.8 — meaning it is “critical” and poses an immediate risk to WordPress sites.
Who discovered it and what is the scope of the exploitation?
The vulnerability in the WordPress Post SMTP plugin was discovered and responsibly reported by security researcher netranger through a bug bounty program; a reward of $7,800 was awarded for the find. Active exploitation attempts — thousands of requests have already been blocked by security systems, while reports indicate ongoing malicious activity.

What risks does this error pose for websites?
The ability to read logged emails means an attacker can bypass authentication processes and gain administrator privileges without additional access. With full privileges, the attacker can install backdoors, modify content, create malicious redirects, or steal user data — impacts that translate into loss of trust, financial damage, and compliance issues.
See also: Vulnerability in React Native CLI puts millions of developers at risk
Recommendations for administrators
Update the Post SMTP plugin to version 3.6.1. Additionally, check your logs for suspicious password resets and detect new or unknown administrators. Implement good security practices: strong, unique passwords, MFA for all accounts with administrator privileges, and restrict access to the admin environment with IP whitelisting where possible. Application security systems and WAFs already have relevant rules in place to mitigate attacks.
Technical attack diagram
The vector is simple: the attacker triggers a password reset for a target account and requests the corresponding log_id via the unprotected interface. If the reset email is retrieved, the link allows a password change and full access to the site — a scenario that leads to the placement of backdoors or redirection of visitors.
Cooperation and defense
Bug bounty discovery and rapid patching demonstrate effective collaboration between researchers and developers, but many sites are lagging behind in upgrading. As interim measures, we recommend disabling email logging, checking logs for suspicious resets, implementing MFA, and restricting access to wp-admin.
See also: Warning! Serious vulnerabilities in Microsoft Teams



Tracking and monitoring
Use web application security (WAF) tools and entry point scanning plugins, enable alerts for abnormal password resets , and check recent user changes. Also, review database permissions and limit logging of sensitive data.
The case is a reminder that even “support” functions like email logs are a significant attack surface when permissions checks are lacking. Prompt notification and proactive monitoring are critical.
Attention to safety must be constant.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
