Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive overview of security vulnerabilities associated with Post SMTP, a robust email deliverability and SMTP solution designed for WordPress environments. It covers a wide range of weakness types, including Cross-Site Scripting (XSS), SQL Injection, and Unrestricted File Uploads, among others that may compromise the integrity of email transmission or user data. The content aggregated here spans from the product's initial release to the most recent advisories, ensuring a complete historical perspective on its security posture. By visiting this page, users can effectively track vendor advisories as they are published, allowing for timely patching and mitigation of potential risks. Additionally, visitors can gain a deeper understanding of specific weakness classes affecting the software, analyzing how different vulnerability types manifest in an email-centric application. The page also serves as a detailed reference for looking up the product's vulnerability history, helping administrators and security professionals assess long-term trends in code quality and security management. This resource is essential for anyone relying on Post SMTP for critical email operations, as it highlights past issues that may indicate persistent architectural weaknesses or areas requiring enhanced secure coding practices. The information is compiled to support informed decision-making regarding upgrades, configuration hardening, and monitoring strategies. Users interested in maintaining a secure email infrastructure can utilize this data to anticipate future threats and implement proactive defense measures. The focus remains strictly on factual vulnerability data without promotional language, ensuring clarity and utility for technical audiences seeking to protect their systems against known exploits.

Vendor: saadiqbal

CVE IDTitleCVSSSeverityPublished
CVE-2026-3090 Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' CWE-79 7.2 High2026-03-18
CVE-2026-2559 Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite CWE-862 5.3 Medium2026-03-18
CVE-2025-12887 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update CWE-862 5.4 Medium2025-12-03
CVE-2025-11833 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure CWE-862 9.8 Critical2025-11-01
CVE-2025-9219 Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update CWE-862 4.3 Medium2025-09-03
CVE-2024-13844 Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter CWE-89 4.9 Medium2025-03-08
CVE-2025-0521 Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2025-02-18
CVE-2024-5207 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection CWE-89 7.2 High2024-05-30
CVE-2023-6875 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API CWE-639 9.8 Critical2024-01-11
CVE-2023-6629 POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg CWE-79 6.1 Medium2024-01-03
CVE-2023-7027 POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device CWE-79 7.2 High2024-01-03
CVE-2021-4422 POST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery Bypass CWE-352 4.3 Medium2023-07-12
CVE-2023-3082 Post SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via Email CWE-79 7.2 High2023-07-12

All 13 known CVE vulnerabilities affecting Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App with full Chinese analysis, references, and POCs where available.