The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This vulnerability affects all versions up to and including 2.8.6 because it does not properly sanitize or escape user input. This means that unauthenticated attackers can inject malicious web scripts into a page which can be executed if a user clicks on a link.