Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks
A weak version of the Post SMTP plugin is being used by over 200,000 WordPress websites, giving hackers access to the administrator account.
With over 400,000 active installs, Post SMTP is a well-liked WordPress email delivery plugin. It is promoted as a more dependable and feature-rich alternative to the built-in "wp_mail()" function.
A security researcher notified WordPress security company PatchStack about the vulnerability on May 23. The vulnerability was given a medium severity score of 8.8 and is currently known as CVE-2025-24000.
Due to a malfunctioning access control mechanism in the plugin's REST API endpoints, which just checked if a user was logged in without determining their permission level, the security flaw impacts all Post SMTP versions up to 3.2.0.
This impli...




