ThreatCluster

Vulnerability in Post SMTP Plugin Exposes 400K WordPress Sites to Account Takeover

First seen 2 Dec 2025, 18:33 UTC Gbhackers 12

Article Content

Browse articles
ThreatCluster

A security vulnerability in the Post SMTP plugin, affecting over 400,000 WordPress sites, allows unauthenticated attackers to take control of administrator accounts. The flaw was reported to Wordfence on October 11, and active exploitation of this vulnerability has been observed. An updated version of the plugin is available to address the issue.