CVE-2024-13362
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
Minimum safe version
3.9.0
Update to 3.9.0 or later to address 34 fixable vulnerabilities
Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update
Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite
Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'
CVE-2025-67563
CVE-2025-12887
CVE-2025-11833
CVE-2025-24000
CVE-2024-13844
Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting
CVE-2025-22800
CVE-2024-52436
CVE-2024-5207
CVE-2024-29128
CVE-2023-6875
CVE-2023-52233
CVE-2023-6621
Post SMTP < 2.6.1 - Authenticated (Administrator+) SQL Injection
CVE-2023-6620
CVE-2023-7027
CVE-2023-6629
CVE-2023-5958
WordPress Post SMTP Mailer/Email Log Plugin < 2.6.1 is vulnerable to SQL Injection
Post SMTP <= 2.6.0 - Authenticated (Administrator+) SQL Injection
WordPress Post SMTP Mailer/Email Log Plugin < 2.5.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-3082
CVE-2021-4422
CVE-2023-3179
CVE-2023-3178
CVE-2021-4342
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
CVE-2022-2352
CVE-2022-2351
WordPress Post SMTP Mailer/Email Log plugin <= 2.0.20 - Cross-Site Request Forgery (CSRF) nonce validation vulnerability