CVE-2025-9219: Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update
The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updatepostsmtpprooptioncallback' function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable pro extensions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9219?
CVE-2025-9219 is considered a medium severity vulnerability due to the potential for unauthorized modification of data.
How do I fix CVE-2025-9219?
To fix CVE-2025-9219, upgrade the Post SMTP WP SMTP Plugin to version 3.4.2 or later, which includes the necessary capability checks.
What are the potential impacts of CVE-2025-9219?
The potential impacts of CVE-2025-9219 include unauthorized data manipulation and possible exploitation by attackers.
Which versions of the Post SMTP WP SMTP Plugin are affected by CVE-2025-9219?
Versions of the Post SMTP WP SMTP Plugin prior to 3.4.2 are affected by CVE-2025-9219.
Is user authentication sufficient to protect against CVE-2025-9219?
No, user authentication alone is insufficient as the vulnerability arises from a missing capability check, allowing unauthorized access.