The POST SMTP plugin for WordPress has a vulnerability that allows attackers to inject harmful code into the plugin. This can lead to sensitive information being accessed by the attacker. The vulnerability exists in all versions up to 2.9.3 and can only be exploited by users with administrator access or higher.