CVE Database /
CVE-2025-11833
CVE · Critical
CVE-2025-11833 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11833
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1 |
Missing Authorization |
Critical
9.8
|
< 3.6.1
|
3.6.1 |
2025-10-31 |
—
|
CVE-2025-11833
The Post SMTP plugin, version 3.6.0 and earlier, is susceptible to unauthorized data access because it lacks proper capability checks in its __construct function. This vulnerability allows unauthenticated users to read any logged emails sent via the plugin, including password reset emails with links, potentially leading to account compromise.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings