Skip to content

CVE-2025-24000

CVE

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 4, 2025
Last Seen
November 4, 2025
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A security vulnerability in the Post SMTP plugin, used in over 400,000 WordPress installations, has been discovered that enables unauthenticated attackers to take control of administrator accounts and entire WordPress sites. The flaw was reported to Wordfence on October 11, and attacks exploiting th...

A critical vulnerability in the Post SMTP plugin, used by over 400,000 WordPress sites, has been discovered, allowing unauthenticated attackers to hijack administrator accounts. The flaw enables attackers to access email logs and reset passwords, compromising entire WordPress instances. A patch for...

Public Exploits

Checking GitHub for proof-of-concept code…