WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-22800 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-22800 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.12 Missing Authorization Medium 4.3 < 2.9.12 2.9.12 2025-01-07

CVE-2025-22800

The Post SMTP plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the regenerate_qrcode() function in versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate QR codes.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.