ThreatCluster

Vulnerability in Post SMTP Plugin Exposes 400K WordPress Sites to Account Takeover

First seen 11 Nov 2025, 16:33 UTC Gbhackers 16

Article Content

Browse articles
ThreatCluster

A vulnerability in the Post SMTP plugin, affecting over 400,000 WordPress installations, allows unauthenticated attackers to take control of administrator accounts. This flaw was reported to Wordfence on October 11, 2025, and active exploitation has been observed. An updated version of the plugin is now available to address this issue.