Vulnerability in Post SMTP Plugin Exposes 400K WordPress Sites to Account Takeover
First seen 11 Nov 2025, 16:33 UTC
•
•16
Export
Article Content
Browse articles
A vulnerability in the Post SMTP plugin, affecting over 400,000 WordPress installations, allows unauthenticated attackers to take control of administrator accounts. This flaw was reported to Wordfence on October 11, 2025, and active exploitation has been observed. An updated version of the plugin is now available to address this issue.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
CVE-2026-2441: Zero-Day CSS Vulnerability in Chromium-Based Browsers
Critical Joomla JCE Vulnerability Under Active Exploitation
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Critical Flaw in Modular DS WordPress Plugin Enables Admin Takeover
Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks