CVE

CVE-2026-3090 — Post SMTP < 3.9.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type'

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-3090 Post SMTP < 3.9.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' Unknown < 3.9.0 3.9.0

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.