SecAlerts
post smtp logo

post smtp

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 19, 2024 to present

10
Total CVEs
6
Critical+High
1
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
49/100
medium
⚠️ 1 Active Exploits

Severity Distribution

Critical
1
High
5
Medium
3
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
SQL Injection
2

Most Affected Products

1. Post SMTP Post SMTP7
2. Wpexperts Post Smtp Wordpress5
3. Post SMTP Post SMTP (WordPress plugin)1
4. Post SMTP Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App1
5. Post SMTP WP SMTP Plugin1

Recent Vulnerabilities

See more →
CVE-2026-48838
CVSS 7.1high

WordPress Post SMTP plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability

6/15/2026🔧 No Patch
CVE-2025-12887
CVSS 5.4medium

Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update

12/3/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-post-smtp-to-hijack-admin-accounts/
unknown

Hackers exploit WordPress plugin Post SMTP to hijack admin accounts

11/4/2025⚠ Exploited🔧 No Patch
CVE-2025-11833
CVSS 9.8critical

Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure

11/1/2025🔧 No Patch
CVE-2025-9219
CVSS 4.3EPSS 0%medium

Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update

9/3/2025🔧 No Patch
CVE-2024-13844
CVSS 4.9medium

Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter

3/8/2025
CVE-2025-0521
CVSS 7.2high

Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

2/18/2025
CVE-2025-22800
CVSS 8.8EPSS 0%high

WordPress Post SMTP plugin <= 2.9.11 - Broken Access Control vulnerability

1/13/2025
CVE-2024-5207
CVSS 7.2EPSS 0%high

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection

5/30/2024🔧 No Patch
CVE-2024-29128
CVSS 7.1EPSS 0%high

WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerability

3/19/2024

Monitor post smtp in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.