CVE-2026-81278: WordPress Post SMTP plugin 4.0.0-beta.1 - Settings Change vulnerability
Published Aug 31, 2026
·Updated
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Post SMTP: from 4.0.0 through beta.1.
Affected Software
1 affected component
Post SMTP>=4.0.0<=4.0.0-beta.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress post smtp pluginto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Aug 31, 2026
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs network access and low privileges. No user interaction is required.
2
What is the likely impact if exploitation succeeds?
The vulnerability can allow unauthorized settings changes. The reported impact is limited to low integrity and availability impact, with no confidentiality impact indicated.