The Post SMTP plugin for WordPress has a problem that could put your website at risk. In versions up to 2.9.9, there is a way for hackers to add harmful code into the plugin. This can allow them to access private information from your website’s database. If you have administrator-level access or above, you could be vulnerable to this attack.