The Post SMTP plugin is a WordPress plugin that is vulnerable to a type of cyberattack called “time-based SQL Injection.” This means that attackers who have administrator-level privileges could use this vulnerability to access sensitive information stored in the database. The vulnerability exists in versions of the plugin up to and including version 2.6.0. It is caused by the software not properly preparing existing SQL queries and not sufficiently escaping user-supplied parameters.