PLUGIN SECURITY
Is Post Smtp safe?
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
What this plugin does
- Slug:
post-smtp - Author: Saad Iqbal
- 300000+ active installs
- 94/100 rating (525 reviews on wordpress.org)
- 20059950 all-time downloads
- On WordPress.org since 2017-10-15
emailemail logsgmail smtpoffice 365smtp
Maintenance status
- Latest known version: 3.9.5
- Last updated: 2026-08-25 4:16am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.1+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
30 known CVEs on file for Post Smtp.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-13362 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.0 | 3.1.0 | 2026-04-30 | ✓ fixed in latest |
| CVE-2026-48838 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 3.6.3 | 3.6.3 | 2026-04-30 | ✓ fixed in latest |
| CVE-2025-67563 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2 | Missing Authorization | Medium 5.3 | < 3.6.2 | 3.6.2 | 2025-12-09 | ✓ fixed in latest |
| CVE-2025-12887 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2 | Missing Authorization | Medium 5.4 | < 3.6.2 | 3.6.2 | 2025-12-03 | ✓ fixed in latest |
| CVE-2025-11833 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1 | Missing Authorization | Critical 9.8 | < 3.6.1 | 3.6.1 | 2025-10-31 | ✓ fixed in latest |
| CVE-2025-24000 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0 | Authentication Bypass Using an Alternate Path or Channel | High 8.8 | < 3.3.0 | 3.3.0 | 2025-07-21 | ✓ fixed in latest |
| CVE-2024-13844 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 3.1.3 | 3.1.3 | 2025-03-07 | ✓ fixed in latest |
| CVE-2025-22800 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.12 | Missing Authorization | Medium 4.3 | < 2.9.12 | 2.9.12 | 2025-01-07 | ✓ fixed in latest |
+ 32 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-52436 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.10 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.6 | < 2.9.10 | 2.9.10 | 2024-11-15 | ✓ fixed in latest |
| CVE-2024-5207 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 2.9.4 | 2.9.4 | 2024-05-22 | ✓ fixed in latest |
| CVE-2024-29128 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.8.7 | 2.8.7 | 2024-03-19 | ✓ fixed in latest |
| CVE-2023-6875 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8 | Authorization Bypass Through User-Controlled Key | Critical 9.8 | < 2.8.8 | 2.8.8 | 2024-01-10 | ✓ fixed in latest |
| CVE-2023-52233 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 | Missing Authorization | High 8.6 | < 2.8.7 | 2.8.7 | 2024-01-05 | ✓ fixed in latest |
| CVE-2023-6621 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.8.7 | 2.8.7 | 2024-01-03 | ✓ fixed in latest |
| CVE-2023-6629 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.8.7 | 2.8.7 | 2024-01-02 | ✓ fixed in latest |
| CVE-2023-7027 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.8.8 | 2.8.8 | 2024-01-02 | ✓ fixed in latest |
| CVE-2023-6620 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.2 | < 2.8.7 | 2.8.7 | 2023-12-21 | ✓ fixed in latest |
| CVE-2023-5958 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.7.1 | 2.7.1 | 2023-11-06 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 | — | Unknown | < 2.6.1 | 2.6.1 | 2023-10-04 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 | — | Unknown | < 2.6.1 | 2.6.1 | 2023-10-03 | ✓ fixed in latest |
| CVE-2023-33999 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.5.8 | 2.5.8 | 2023-07-18 | ✓ fixed in latest |
| CVE-2023-3082 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.5.8 | 2.5.8 | 2023-07-11 | ✓ fixed in latest |
| CVE-2023-3178 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.5.7 | 2.5.7 | 2023-06-26 | ✓ fixed in latest |
| CVE-2023-3179 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 2.5.7 | 2.5.7 | 2023-06-26 | ✓ fixed in latest |
| CVE-2021-4342 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 | — | Unknown | < 2.0.21 | 2.0.21 | 2023-06-07 | ✓ fixed in latest |
| CVE-2022-2352 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.7 | Server-Side Request Forgery (SSRF) | High 7.2 | < 2.1.7 | 2.1.7 | 2022-09-05 | ✓ fixed in latest |
| CVE-2022-2351 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.1.4 | 2.1.4 | 2022-08-18 | ✓ fixed in latest |
| CVE-2021-4422 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 2.0.21 | 2.0.21 | 2021-03-01 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 | — | Unknown | < 2.0.21 | 2.0.21 | 2021-02-11 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.0 | 3.1.0 | 0000-00-00 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.9.0 | — | Unknown | < 3.9.0 | 3.9.0 | 0000-00-00 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.9.0 | — | Unknown | < 3.9.0 | 3.9.0 | 0000-00-00 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.4.2 | — | Medium 4.3 | < 3.4.2 | 3.4.2 | 0000-00-00 | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 | — | Unknown | < 2.0.21 | 2.0.21 | — | ✓ fixed in latest |
| — | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 | — | Unknown | < 2.6.1 | 2.6.1 | — | ✓ fixed in latest |
| — | Post SMTP < 2.6.1 - Authenticated (Administrator+) SQL Injection | — | Unknown | < 2.6.1 | 2.6.1 | — | ✓ fixed in latest |
| CVE-2025-0521 | Post SMTP < 3.1.0 - Unauthenticated Stored XSS | — | Unknown | < 3.1.0 | 3.1.0 | — | ✓ fixed in latest |
| CVE-2025-9219 | Post SMTP < 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update | — | Unknown | < 3.4.2 | 3.4.2 | — | ✓ fixed in latest |
| CVE-2026-2559 | Post SMTP < 3.9.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite | — | Unknown | < 3.9.0 | 3.9.0 | — | ✓ fixed in latest |
| CVE-2026-3090 | Post SMTP < 3.9.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' | — | Unknown | < 3.9.0 | 3.9.0 | — | ✓ fixed in latest |
How to fix it
Keep Post Smtp updated — 3.9.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin — 4000000+ active installs — 96/100 (5181) — max PHP 8.4
- MC4WP: Mailchimp for WordPress — 1000000+ active installs — 96/100 (1496) — max PHP 8.4
- Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more — 500000+ active installs — 92/100 (707) — max PHP 8.4
- WP Mail Logging — 300000+ active installs — 94/100 (365)
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.