CVE · High

CVE-2026-48838 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-48838 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.6.3 3.6.3 2026-04-30

CVE-2026-48838

The Post SMTP plugin for WordPress, versions 3.6.2 and earlier, is susceptible to stored cross-site scripting (XSS) due to inadequate input sanitization and output handling. This vulnerability allows unauthenticated attackers to inject malicious scripts into pages that can be executed whenever a user views them.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.