The WordPress plugin YaySMTP is vulnerable to an attack called Stored Cross-Site Scripting. This type of attack can allow unauthorised people to inject malicious scripts into pages which will run whenever someone visits them. This vulnerability affects all versions of YaySMTP up to and including version 2.4.5, as the plugin does not properly protect against this type of attack.