CVE · High

CVE-2025-24000 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24000 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0 Authentication Bypass Using an Alternate Path or Channel High 8.8 < 3.3.0 3.3.0 2025-07-21

CVE-2025-24000

The Post SMTP plugin, version 3.2.0 and earlier, is susceptible to privilege escalation through account takeover due to insufficient capability verification in the get_details() function. Authenticated users with subscriber-level access or higher can exploit this flaw to view email logs that may include password reset information, potentially leading to unauthorized access to other user accounts, including those of administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.