The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin has a security vulnerability that affects all versions up to, and including, 2.8.7. This vulnerability allows unauthenticated attackers to inject malicious code into pages on the website. When a user visits an infected page, the code will be executed. This is due to the plugin not properly sanitizing and escaping user input.