Hackers exploit WordPress plugin Post SMTP to hijack admin accounts

A serious flaw in the Post SMTP plugin, which is deployed on over 400,000 WordPress websites, is being actively exploited by threat actors to gain total access by taking over administrator accounts.

A well-liked email distribution method called Post SMTP is promoted as a feature-rich and more dependable substitute for the built-in “wp_mail()” function.

Researcher “netranger” reported an email log disclosure problem that might be used for account takeover attempts to WordPress security company Wordfence on October 11. With a critical-severity level of 9.8, the problem—tracked as CVE-2025-11833—affects all Post SMTP versions 3.6.0 and below.

The “_construct” method of the plugin’s “PostmanEmailLogs” flow lacks authorization checks which is the root of the vulnerability read more about Hackers exploit WordPress plugin Post SMTP to hijack admin accounts.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *