CVE-2025-22800: WordPress Post SMTP plugin <= 2.9.11 - Broken Access Control vulnerability
Published Jan 13, 2025
·Updated
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.
Affected Software
3 affected components
Post SMTP Post SMTP<=2.9.11
WordPress Post SMTP plugin<=2.9.11
Wpexperts Post Smtp Wordpress<2.9.12
Remediation
Information
Update the WordPress Post SMTP wordpress plugin to the latest available version (at least 2.9.12).
Event History
Jan 13, 2025
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22800?
CVE-2025-22800 has been classified as a critical vulnerability due to its potential for unauthorized access and exploitation.
2
How do I fix CVE-2025-22800?
To fix CVE-2025-22800, update the Post SMTP plugin to version 2.9.12 or later to address the missing authorization issue.
3
What versions are affected by CVE-2025-22800?
CVE-2025-22800 affects Post SMTP versions up to and including 2.9.11.
4
What type of vulnerability is CVE-2025-22800?
CVE-2025-22800 is a Missing Authorization vulnerability that allows exploitation due to incorrectly configured access control.
5
Who is affected by CVE-2025-22800?
Any users of the Post SMTP plugin for WordPress versions up to 2.9.11 may be affected by CVE-2025-22800.