+ 27 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-52436
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.10 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,6
|
< 2.9.10
|
2.9.10 |
2024-11-15 |
—
|
|
CVE-2024-5207
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.4 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,2
|
< 2.9.4
|
2.9.4 |
2024-05-22 |
—
|
|
CVE-2024-29128
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 2.8.7
|
2.8.7 |
2024-03-19 |
—
|
|
CVE-2023-6875
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8 |
Elusión de autorización mediante una clave controlada por el usuario |
Crítica
9,8
|
< 2.8.8
|
2.8.8 |
2024-01-10 |
—
|
|
CVE-2023-52233
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 |
Falta de control de autorización |
Alta
8,6
|
< 2.8.7
|
2.8.7 |
2024-01-05 |
—
|
|
CVE-2023-6621
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.8.7
|
2.8.7 |
2024-01-03 |
—
|
|
CVE-2023-6629
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.8.7
|
2.8.7 |
2024-01-02 |
—
|
|
CVE-2023-7027
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2.8.8
|
2.8.8 |
2024-01-02 |
—
|
|
CVE-2023-6620
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 |
Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) |
Alta
7,2
|
< 2.8.7
|
2.8.7 |
2023-12-21 |
—
|
|
CVE-2023-5958
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.7.1
|
2.7.1 |
2023-11-06 |
—
|
|
—
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 |
— |
Desconocido
|
< 2.6.1
|
2.6.1 |
2023-10-04 |
—
|
|
—
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 |
— |
Desconocido
|
< 2.6.1
|
2.6.1 |
2023-10-03 |
—
|
|
CVE-2023-33999
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 2.5.8
|
2.5.8 |
2023-07-18 |
—
|
|
CVE-2023-3082
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 2.5.8
|
2.5.8 |
2023-07-11 |
—
|
|
CVE-2023-3178
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.5.7
|
2.5.7 |
2023-06-26 |
—
|
|
CVE-2023-3179
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
8,8
|
< 2.5.7
|
2.5.7 |
2023-06-26 |
—
|
|
CVE-2021-4342
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 |
— |
Desconocido
|
< 2.0.21
|
2.0.21 |
2023-06-07 |
—
|
|
CVE-2022-2352
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.7 |
Falsificación de petición del lado del servidor (SSRF) |
Alta
7,2
|
< 2.1.7
|
2.1.7 |
2022-09-05 |
—
|
|
CVE-2022-2351
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 2.1.4
|
2.1.4 |
2022-08-18 |
—
|
|
CVE-2021-4422
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 2.0.21
|
2.0.21 |
2021-03-01 |
—
|
|
—
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 |
— |
Desconocido
|
< 2.0.21
|
2.0.21 |
2021-02-11 |
—
|
|
CVE-2025-0521
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 3.1.0
|
3.1.0 |
0000-00-00 |
—
|
|
CVE-2026-3090
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.9.0 |
— |
Desconocido
|
< 3.9.0
|
3.9.0 |
0000-00-00 |
—
|
|
CVE-2026-2559
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.9.0 |
— |
Desconocido
|
< 3.9.0
|
3.9.0 |
0000-00-00 |
—
|
|
—
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.4.2 |
— |
Media
4,3
|
< 3.4.2
|
3.4.2 |
0000-00-00 |
—
|
|
—
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 |
— |
Desconocido
|
< 2.0.21
|
2.0.21 |
— |
—
|
|
—
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 |
— |
Desconocido
|
< 2.6.1
|
2.6.1 |
— |
—
|
CVE-2024-52436
The Post SMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-5207
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator access or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-29128
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.8.7).
Le Ngoc Anh discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.8.7.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6875
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.8.8).
Ulyses Saicha discovered and reported this Broken Authentication vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website. This vulnerability has been fixed in version 2.8.8.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-52233
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.8.7).
Yuchen Ji discovered and reported this Broken Access Control vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.8.7.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6621
The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-6629
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘msg’ parameter in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE-2023-6621 appears to be a duplicate of this issue. CVE-2024-29128 appears to be a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-7027
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.8.8).
Sean Murphy discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.8.8.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-6620
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.8.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator access or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-5958
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email message content in all versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.6.1).
WordFence discovered and reported this SQL Injection vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 2.6.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1
The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-33999
Update the plugin to the latest version.
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.5.8.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-3082
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.5.8).
Alex Thomas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.5.8.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-3178
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.5.7).
Erwan LR (WPScan) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Post SMTP Mailer/Email Log Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 2.5.7.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-3179
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. This is due to incorrect nonce validation on the resend_email() function. This makes it possible for unauthenticated attackers to resend emails to an arbitrary email address via a forged request granted they can trick a site user with the manage_postman_smtp capability into performing an action such as clicking on a link. An attacker could leverage this to resend a password reset email to their own account and compromise a site administrators account.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-4342
CVE split into individual CVE IDs for each software record.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-2352
Authenticated Blind Server-Side Request Forgery (SSRF) vulnerability discovered by Raad Haddad (Cloudyrion GmbH) in WordPress Post SMTP Mailer/Email Log plugin (versions <= 2.1.6).
Update the WordPress Post SMTP Mailer/Email Log plugin to the latest available version (at least 2.1.7).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-2351
The Post SMTP Mailer/Email Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘input_tmp_dir’ parameter in versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-4422
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21
Cross-Site Request Forgery (CSRF) nonce validation vulnerability found in WordPress Post SMTP Mailer/Email Log plugin (versions <= 2.0.20).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2025-0521
The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-3090
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is only exploitable when the Post SMTP Pro plugin is also installed and its Reporting and Tracking extension is enabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2559
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the site's Office 365 OAuth mail configuration (access token, refresh token, and user email) via a crafted URL. The configuration option is used during wizard setup of Microsoft365 SMTP, only available in the Pro option of the plugin. This could cause an Administrator to believe an attacker-controlled Azure app is their own, and lead them to connect the plugin to the attacker's account during configuration after upgrading to Pro.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.4.2
The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_post_smtp_pro_option_callback' function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable pro extensions.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1
The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.