Post SMTP Plugin Flaw Risked 400K+ WordPress Sites

Hey WordPress admins, have you heard about the latest update you need to make on your website? The Post SMTP plugin had a serious vulnerability that could have allowed hackers to take over your admin accounts. This flaw was a big deal, especially considering that over 400,000 websites were at risk due to the widespread use of this plugin.

Fixing the Account Takeover Issue in Post SMTP WordPress Plugin

A recent post from Patchstack highlighted a major vulnerability in the Post SMTP plugin. By exploiting this flaw, attackers could gain higher privileges on your website by hijacking admin accounts.

The problem stemmed from multiple Broken Access Control vulnerabilities in the plugin’s REST API endpoints. This meant that even a low-privileged user, such as a Subscriber, could potentially escalate their privileges and carry out unauthorized actions.

This flaw allowed any registered user, even those with Subscriber-level access, to do things like view email statistics, resend emails, and most alarmingly, access detailed email logs including the entire email content.
This level of access could enable a Subscriber-level user to intercept any email sent from your WordPress site, including password reset emails.

The issue was specifically with the get_logs_permission function, which didn’t perform additional checks beyond user permission validation. This oversight granted authorized users access to any REST API, ultimately leading to admin account takeover.

Don’t Forget to Update Your Websites

If you’re using Post SMTP versions 3.2.0 or below, you’re at risk. The vulnerabilities, designated as CVE-2025-24000, were discovered by Denver Jackson and promptly patched in version 3.3.0. Make sure to update to this version or later to safeguard your website.

Post SMTP is a popular plugin for managing email delivery in WordPress. It offers various features like email logging, DNS validation, OAuth 2.0 support, and fallback mailing to enhance email sending capabilities.

With over 400,000 active installations according to its WordPress listing, Post SMTP is widely used. This also means that the threat posed by unpatched vulnerabilities is significant. So, make sure to stay updated with the latest plugin releases to stay protected.

We’d love to hear your thoughts in the comments section below!

Leave a Reply

Your email address will not be published. Required fields are marked *