First published: Mon Jan 13 2025(Updated: )
Missing Authorization vulnerability in Post SMTP Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through 2.9.11.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Post SMTP | <=2.9.11 | |
WordPress Post SMTP Plugin | <=2.9.11 |
Update the WordPress Post SMTP wordpress plugin to the latest available version (at least 2.9.12).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22800 has been classified as a critical vulnerability due to its potential for unauthorized access and exploitation.
To fix CVE-2025-22800, update the Post SMTP plugin to version 2.9.12 or later to address the missing authorization issue.
CVE-2025-22800 affects Post SMTP versions up to and including 2.9.11.
CVE-2025-22800 is a Missing Authorization vulnerability that allows exploitation due to incorrectly configured access control.
Any users of the Post SMTP plugin for WordPress versions up to 2.9.11 may be affected by CVE-2025-22800.