CVE-2025-12887: Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update
The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handlegmailoauthredirect' function. This makes it possible for authenticated attackers, with subscriber level access and above, to inject invalid or attacker-controlled OAuth credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12887?
CVE-2025-12887 is considered a medium severity vulnerability due to its potential for authorization bypass.
How do I fix CVE-2025-12887?
To fix CVE-2025-12887, update the Post SMTP plugin to version 3.6.2 or higher.
What versions are affected by CVE-2025-12887?
CVE-2025-12887 affects all versions of the Post SMTP plugin up to and including 3.6.1.
What type of vulnerability is CVE-2025-12887?
CVE-2025-12887 is classified as an authorization bypass vulnerability.
Who is impacted by CVE-2025-12887?
Users of the Post SMTP plugin for WordPress versions up to 3.6.1 are impacted by CVE-2025-12887.