The WordPress plugin called POST SMTP, which is used for sending emails and tracking delivery issues, has a security vulnerability. This vulnerability allows attackers with administrator access or higher to inject extra code into the plugin, which could then be used to access sensitive information from the website’s database. This vulnerability affects all versions of the plugin up to version 2.8.6.