What the vulnerability does
01Description
Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
What the vulnerability does
Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.
Explanation of Vulnerability in Simple Terms
Post SMTP Mailer/Email Log versions up to 2.8.6 lack proper authorization checks, allowing unauthenticated attackers to modify email settings and logs over the network. An attacker can change mail server configuration, intercept emails, or delete audit records without needing valid credentials or user interaction. This affects any WordPress site running the vulnerable plugin.
What an attacker can do
Modify email settings, intercept messages, or delete email logs without authentication.
Potential impact on your site
Attackers can hijack outgoing email, compromise password resets, or erase evidence of their activity.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities