Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

22 known CVEs 300K+ active installs

Scan My Site Free

UNKNOWN: 22
Known Vulnerabilities 22
CVE-2026-2559 UNKNOWN EPSS 0.1%
Published 2026-03-18 · Affected: *
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and i
CVE-2025-12887 UNKNOWN EPSS 0.2%
Published 2025-12-03 · Affected: *
The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to upda
CVE-2025-22800 UNKNOWN EPSS 0.3%
Published 2025-01-13 · Affected: *
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.
CVE-2025-22800 UNKNOWN EPSS 0.3%
Published 2025-01-13 · Affected: *
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.
CVE-2025-22800 UNKNOWN EPSS 0.3%
Published 2025-01-13 · Affected: *
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.
CVE-2025-22800 UNKNOWN EPSS 0.3%
Published 2025-01-13 · Affected: *
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.
CVE-2024-52436 UNKNOWN EPSS 0.4%
Published 2024-11-18 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a t
CVE-2024-52436 UNKNOWN EPSS 0.4%
Published 2024-11-18 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a t
CVE-2024-52436 UNKNOWN EPSS 0.4%
Published 2024-11-18 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a t
CVE-2024-52436 UNKNOWN EPSS 0.4%
Published 2024-11-18 · Affected: *
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a t
CVE-2024-5207 UNKNOWN EPSS 0.4%
Published 2024-05-30 · Affected: *
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in
CVE-2024-5207 UNKNOWN EPSS 0.4%
Published 2024-05-30 · Affected: *
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in
CVE-2023-6875 UNKNOWN EPSS 1.0%
Published 2024-01-11 · Affected: *
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a ty
CVE-2023-6875 UNKNOWN EPSS 1.0%
Published 2024-01-11 · Affected: *
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a ty
CVE-2023-7027 UNKNOWN EPSS 0.6%
Published 2024-01-03 · Affected: *
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versi
CVE-2023-7027 UNKNOWN EPSS 0.6%
Published 2024-01-03 · Affected: *
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versi
CVE-2023-6629 UNKNOWN EPSS 0.4%
Published 2024-01-03 · Affected: *
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all ve
CVE-2023-6629 UNKNOWN EPSS 0.4%
Published 2024-01-03 · Affected: *
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all ve
CVE-2021-4422 UNKNOWN EPSS 0.4%
Published 2023-07-12 · Affected: *
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExp
CVE-2021-4422 UNKNOWN EPSS 0.4%
Published 2023-07-12 · Affected: *
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExp
CVE-2023-3082 UNKNOWN EPSS 0.4%
Published 2023-07-12 · Affected: *
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. T
CVE-2023-3082 UNKNOWN EPSS 0.4%
Published 2023-07-12 · Affected: *
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping. T

Is Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP &amp; Mobile App running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free