CVE · Medium

CVE-2024-13844 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13844 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 3.1.3 3.1.3 2025-03-07

CVE-2024-13844

The Post SMTP plugin for WordPress contains a generic SQL injection vulnerability affecting versions 3.1.2 and earlier through the 'columns' parameter, which is not properly escaped and insufficiently prepared in SQL queries. Authenticated administrators and higher-privileged users can exploit this flaw to inject additional SQL commands and extract sensitive database information. The vulnerability has been fixed in version 3.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.