CVE Database /
CVE-2025-24000
CVE · High
CVE-2025-24000 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-24000
|
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0 |
Authentication Bypass Using an Alternate Path or Channel |
High
8.8
|
< 3.3.0
|
3.3.0 |
2025-07-21 |
—
|
CVE-2025-24000
The Post SMTP plugin, version 3.2.0 and earlier, is susceptible to privilege escalation through account takeover due to insufficient capability verification in the get_details() function. Authenticated users with subscriber-level access or higher can exploit this flaw to view email logs that may include password reset information, potentially leading to unauthorized access to other user accounts, including those of administrators.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings