Vulnerability in Post SMTP Plugin Exposes 400K WordPress Sites to Account Takeover
First seen 2 Dec 2025, 18:33 UTC
•
•12
Export
Article Content
Browse articles
A security vulnerability in the Post SMTP plugin, affecting over 400,000 WordPress sites, allows unauthenticated attackers to take control of administrator accounts. The flaw was reported to Wordfence on October 11, and active exploitation of this vulnerability has been observed. An updated version of the plugin is available to address the issue.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers
Critical Joomla JCE Vulnerability Under Active Exploitation
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Critical Flaw in Modular DS WordPress Plugin Enables Admin Takeover
Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks