PLUGIN SECURITY

Is Post Smtp safe?

Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.

What this plugin does

  • Slug: post-smtp
  • Author: Saad Iqbal
  • 300000+ active installs
  • 94/100 rating (525 reviews on wordpress.org)
  • 20059950 all-time downloads
  • On WordPress.org since 2017-10-15

emailemail logsgmail smtpoffice 365smtp

Maintenance status

  • Latest known version: 3.9.5
  • Last updated: 2026-08-25 4:16am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.1+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

30 known CVEs on file for Post Smtp.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13362 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.0 3.1.0 2026-04-30 ✓ fixed in latest
CVE-2026-48838 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.6.3 3.6.3 2026-04-30 ✓ fixed in latest
CVE-2025-67563 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2 Missing Authorization Medium 5.3 < 3.6.2 3.6.2 2025-12-09 ✓ fixed in latest
CVE-2025-12887 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2 Missing Authorization Medium 5.4 < 3.6.2 3.6.2 2025-12-03 ✓ fixed in latest
CVE-2025-11833 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1 Missing Authorization Critical 9.8 < 3.6.1 3.6.1 2025-10-31 ✓ fixed in latest
CVE-2025-24000 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0 Authentication Bypass Using an Alternate Path or Channel High 8.8 < 3.3.0 3.3.0 2025-07-21 ✓ fixed in latest
CVE-2024-13844 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 3.1.3 3.1.3 2025-03-07 ✓ fixed in latest
CVE-2025-22800 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.12 Missing Authorization Medium 4.3 < 2.9.12 2.9.12 2025-01-07 ✓ fixed in latest
+ 32 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-52436 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.10 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 2.9.10 2.9.10 2024-11-15 ✓ fixed in latest
CVE-2024-5207 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 2.9.4 2.9.4 2024-05-22 ✓ fixed in latest
CVE-2024-29128 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.8.7 2.8.7 2024-03-19 ✓ fixed in latest
CVE-2023-6875 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8 Authorization Bypass Through User-Controlled Key Critical 9.8 < 2.8.8 2.8.8 2024-01-10 ✓ fixed in latest
CVE-2023-52233 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Missing Authorization High 8.6 < 2.8.7 2.8.7 2024-01-05 ✓ fixed in latest
CVE-2023-6621 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.7 2.8.7 2024-01-03 ✓ fixed in latest
CVE-2023-6629 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.7 2.8.7 2024-01-02 ✓ fixed in latest
CVE-2023-7027 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.8.8 2.8.8 2024-01-02 ✓ fixed in latest
CVE-2023-6620 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.8.7 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 2.8.7 2.8.7 2023-12-21 ✓ fixed in latest
CVE-2023-5958 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.7.1 2.7.1 2023-11-06 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 Unknown < 2.6.1 2.6.1 2023-10-04 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 Unknown < 2.6.1 2.6.1 2023-10-03 ✓ fixed in latest
CVE-2023-33999 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 2.5.8 2.5.8 2023-07-18 ✓ fixed in latest
CVE-2023-3082 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.5.8 2.5.8 2023-07-11 ✓ fixed in latest
CVE-2023-3178 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.5.7 2.5.7 2023-06-26 ✓ fixed in latest
CVE-2023-3179 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.5.7 Cross-Site Request Forgery (CSRF) High 8.8 < 2.5.7 2.5.7 2023-06-26 ✓ fixed in latest
CVE-2021-4342 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 Unknown < 2.0.21 2.0.21 2023-06-07 ✓ fixed in latest
CVE-2022-2352 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.7 Server-Side Request Forgery (SSRF) High 7.2 < 2.1.7 2.1.7 2022-09-05 ✓ fixed in latest
CVE-2022-2351 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.1.4 2.1.4 2022-08-18 ✓ fixed in latest
CVE-2021-4422 Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.0.21 2.0.21 2021-03-01 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 Unknown < 2.0.21 2.0.21 2021-02-11 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.0 3.1.0 0000-00-00 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.9.0 Unknown < 3.9.0 3.9.0 0000-00-00 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.9.0 Unknown < 3.9.0 3.9.0 0000-00-00 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.4.2 Medium 4.3 < 3.4.2 3.4.2 0000-00-00 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.0.21 Unknown < 2.0.21 2.0.21 ✓ fixed in latest
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.6.1 Unknown < 2.6.1 2.6.1 ✓ fixed in latest
Post SMTP < 2.6.1 - Authenticated (Administrator+) SQL Injection Unknown < 2.6.1 2.6.1 ✓ fixed in latest
CVE-2025-0521 Post SMTP < 3.1.0 - Unauthenticated Stored XSS Unknown < 3.1.0 3.1.0 ✓ fixed in latest
CVE-2025-9219 Post SMTP < 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update Unknown < 3.4.2 3.4.2 ✓ fixed in latest
CVE-2026-2559 Post SMTP < 3.9.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite Unknown < 3.9.0 3.9.0 ✓ fixed in latest
CVE-2026-3090 Post SMTP < 3.9.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' Unknown < 3.9.0 3.9.0 ✓ fixed in latest

How to fix it

Keep Post Smtp updated — 3.9.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.