CVE-2025-24000: WordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post SMTP: from n/a through <= 3.2.0.
Other sources
Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass.This issue affects Post SMTP: from n/a through 3.2.0.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24000?
CVE-2025-24000 is rated as a high severity authentication bypass vulnerability.
How do I fix CVE-2025-24000?
To fix CVE-2025-24000, update the WPExperts Post SMTP plugin to version 3.2.1 or later.
Who is affected by CVE-2025-24000?
CVE-2025-24000 affects all versions of WPExperts Post SMTP up to and including 3.2.0.
What type of attacks can be executed due to CVE-2025-24000?
CVE-2025-24000 allows attackers to bypass authentication mechanisms, potentially leading to site hijacking.
When was CVE-2025-24000 disclosed?
CVE-2025-24000 was disclosed on an unspecified date, highlighting vulnerabilities in versions of the plugin prior to 3.2.1.