What the vulnerability does
01Description
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover. CVE-2023-52233 appears to be a duplicate of this issue.
Explanation of Vulnerability in Simple Terms
02Summary
Post SMTP versions up to 2.8.7 contain a critical vulnerability allowing unauthenticated attackers to read sensitive data, modify site content, or disrupt service via network requests. No user interaction or special privileges are required. The vulnerability affects the core functionality of the plugin and can be exploited remotely without authentication.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, or disrupt service without authentication.
Potential impact on your site
04Site Impact
Attackers can compromise your site's email configuration, read logs, and potentially access or modify site data.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 11, 2024
CVE published
April 8, 2026
Record updated