PT-2025-11223 · WordPress · Post Smtp

Denver Jackson

·

Published

2025-03-13

·

Updated

2025-09-11

·

CVE-2025-24000

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Post SMTP plugin for WordPress (affected versions not specified)
Description The Post SMTP plugin for WordPress is subject to a security issue that allows for full site takeover. Approximately 400,000 WordPress sites are potentially at risk. This issue is actively being exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09371
CVE-2025-24000

Affected Products

Post Smtp