The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack can allow unauthenticated attackers to inject malicious web scripts into pages which will be executed any time a user visits the injected page. This vulnerability affects all versions of the plugin up to and including version 2.7.0. The vulnerability is caused by a lack of input sanitization and output escaping.