CVE · High

CVE-2023-52233 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-52233 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Missing Authorization High 8.6 < 2.8.7 2.8.7 2024-01-05

CVE-2023-52233

The Post SMTP Mailer/Email Log plugin for WordPress contained a broken access control vulnerability prior to version 2.8.7 that allowed unauthenticated or low-privileged users to perform administrative actions due to missing authorization and nonce verification checks. This flaw, discovered by Yuchen Ji, could be exploited by attackers to execute functions normally restricted to higher-privileged users. Users should upgrade to version 2.8.7 or later to remediate this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.