Vulnerability in Post SMTP Plugin Allows Account Takeover on 400K WordPress Sites
First seen 5 Nov 2025, 17:08 UTC
•

•85% similarity
•59.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A security vulnerability in the Post SMTP plugin, used in over 400,000 WordPress installations, has been discovered that enables unauthenticated attackers to take control of administrator accounts and entire WordPress sites. The flaw was reported to Wordfence on October 11, and attacks exploiting this vulnerability have already been observed. An updated version of the plugin is available to mitigate the risk.
ThreatCluster AI
How this analysis works