Vulnerability in Post SMTP Plugin Allows Account Takeover on 400K WordPress Sites

Vulnerability in Post SMTP Plugin Allows Account Takeover on 400K WordPress Sites

First seen 5 Nov 2025, 17:08 UTC Heise.DeBleepingcomputerDarkreading 85% similarity 59.4

Article Content

Browse articles
ThreatCluster

A security vulnerability in the Post SMTP plugin, used in over 400,000 WordPress installations, has been discovered that enables unauthenticated attackers to take control of administrator accounts and entire WordPress sites. The flaw was reported to Wordfence on October 11, and attacks exploiting this vulnerability have already been observed. An updated version of the plugin is available to mitigate the risk.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story