Input validation vulnerability in POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress 2.6.1

The Post SMTP plugin is a WordPress plugin that is vulnerable to a type of cyberattack called “time-based SQL Injection.” This means that attackers who have administrator-level privileges could use this vulnerability to access sensitive information stored in the database. The vulnerability exists in versions of the plugin up to and including version 2.6.0. It is caused by the software not properly preparing existing SQL queries and not sufficiently escaping user-supplied parameters.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.