SecAlerts
p

post smtp

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 19, 2024 to present

10
Total CVEs
6
Critical+High
1
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
49/100
medium
⚠️ 1 Active Exploits

Severity Distribution

Critical
1
High
5
Medium
3
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
SQL Injection
2

Most Affected Products

1. Post SMTP Post SMTP7
2. Wpexperts Post Smtp Wordpress5
3. Post SMTP Post SMTP (WordPress plugin)1
4. Post SMTP Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App1
5. Post SMTP WP SMTP Plugin1

Recent Vulnerabilities

See more →
CVE-2026-48838
CVSS 7.1high

WordPress Post SMTP plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability

Jun 15, 2026🔧 No Patch
CVE-2025-12887
CVSS 5.4medium

Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update

Dec 3, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/hackers-exploit-wordpress-plugin-post-smtp-to-hijack-admin-accounts/
unknown

Hackers exploit WordPress plugin Post SMTP to hijack admin accounts

Nov 4, 2025⚠ Exploited🔧 No Patch
CVE-2025-11833
CVSS 9.8critical

Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure

Nov 1, 2025🔧 No Patch
CVE-2025-9219
CVSS 4.3EPSS 0%medium

Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update

Sep 3, 2025🔧 No Patch
CVE-2024-13844
CVSS 4.9medium

Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter

Mar 8, 2025
CVE-2025-0521
CVSS 7.2high

Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

Feb 18, 2025
CVE-2025-22800
CVSS 8.8EPSS 0%high

WordPress Post SMTP plugin <= 2.9.11 - Broken Access Control vulnerability

Jan 13, 2025
CVE-2024-5207
CVSS 7.2EPSS 0%high

POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection

May 30, 2024🔧 No Patch
CVE-2024-29128
CVSS 7.1EPSS 0%high

WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerability

Mar 19, 2024

Monitor post smtp in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.