The POST SMTP Mailer plugin for WordPress has a security issue that allows unauthorized users to access and change data. This is due to a problem with the connect-app REST endpoint in all versions up to 2.8.7. This means that attackers without proper authentication can reset the API key and view logs, including password reset emails, which could lead to taking over the website. This vulnerability has been identified as CVE-2023-52233.