CVE · Critical

CVE-2025-11833 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11833 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1 Missing Authorization Critical 9.8 < 3.6.1 3.6.1 2025-10-31

CVE-2025-11833

The Post SMTP plugin, version 3.6.0 and earlier, is susceptible to unauthorized data access because it lacks proper capability checks in its __construct function. This vulnerability allows unauthenticated users to read any logged emails sent via the plugin, including password reset emails with links, potentially leading to account compromise.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.