Post SMTP plug-in — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 5, 2025
Last Seen
November 5, 2025

Post SMTP plug-in is a technology platform tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 5, 2025; most recent activity November 5, 2025.

Overview

Post SMTP is a WordPress plug-in used to handle SMTP email delivery for WordPress sites. A critical flaw in this plug-in has been disclosed, potentially allowing an attacker to take over affected sites and compromising up to 400,000 WordPress installations, underscoring the risk posed by vulnerable third-party plugins in the WordPress ecosystem.

Related Threat Clusters

Recent Intelligence Reports

  • Critical Site Takeover Flaw Affects 400K WordPress Sites — Darkreading · November 5, 2025

CVSS v3.1 Breakdown