Input validation vulnerability in Post SMTP – WordPress SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more 3.0.2

The Post SMTP plugin used for WordPress has a security issue where hackers can insert harmful website code in pages by exploiting the “from” and “subject” parameters. This can be done by attackers who are not logged in, and it affects all versions up to 3.0.2. This could lead to the execution of unauthorized scripts when a user visits the affected page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.