
[CIVN-2025-0312] Missing Authorization check in the Post SMTP plugin for WordPress
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Missing Authorization check in the Post SMTP plugin for WordPress
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
WordPress Plugin Post SMTP versions 3.6.0 and prior
Overview
A vulnerability has been reported in the Post SMTP plugin for WordPress, which could allow an unauthenticated attacker to access sensitive information on the targeted system.
Target Audience:
Users of affected WordPress Plugins.
Risk Assessment:
High risk of unauthorised access.
Impact Assessment:
Potential for account takeover.
Description
Post SMTP is a WordPress plugin that ensures reliable email delivery by using proper SMTP authentication, offering detailed logs, delivery alerts, backup SMTP options, and mobile app notifications.
The vulnerability in the Post SMTP plugin for WordPress exists due to a missing authorisation check on the construct function.
Successful exploitation of this vulnerability could allow an unauthenticated attacker, which could allow an unauthenticated attacker to access sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned:
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-smtp/post-smtp-complete-smtp-solution-with-logs-alerts-backup-smtp-mobile-app-360-missing-authorization-to-account-takeover-via-unauthenticated-email-log-disclosure
Vendor Information
Post SMTP
https://wordpress.org/plugins/post-smtp/
References
WordFence
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/post-smtp/post-smtp-complete-smtp-solution-with-logs-alerts-backup-smtp-mobile-app-360-missing-authorization-to-account-takeover-via-unauthenticated-email-log-disclosure
CVE Name
CVE-2025-11833
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIyBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmkV9osACgkQ3jCgcSdc
ys8oJA/1Gvb4XBBi68Kee8qHp9EGh8vxRxfMS1U/atgyb2feH/Yo5jHkf4gOvEvK
ci2tgcTnvDBw1x8nHQhDxR6nXQmIKs+1IztAHeJYQct0ycu7Zf4kHEYdVtNLMGTa
vsvc+Ew9P9R59zpXARjqzAoSmokdb4poVvutmUOy2xeByDFtjIDEG6B3EpCBuGV+
I+0VQ+02BlPiYXXHpKEwSXLZbe2Ua11nIwjfA5qKzBSEkzXXDwOuuXe+S5Foo861
hq11RWLK+OnCxNFxCWEqSEUxw+4HRUs+C0Rz/MeREsdMw1Xv9pC2i070uXNid63E
NYn+6l+znPAdQqskOvd10An0Y8X2JhvFUpZJCJfEHNUsQroN06ygt7TkQt8mJUnQ
h2bn3sPcYvKc5ngdHcq7QtE/sBxWbG5m2EFf0azBb+YG1OAB6dzrsQXClVXE8GP3
rf6GgoGAGyMN6Als1vW2O9tpVbTm6/60THGdQbb8ypfCSV/LUj+SIDRO1oDxe27u
mXYvPMJrCmu7OGsFwt5k+O9QCbIVvoMjThDG1Jld9SMgxNqXwMUsGJhft0hjUHeG
DCOTZGgOZ60t49f3lzBmWJeszY2q2Q7gnQ4Cc5wPwOBrpzpCBpQkMfoyiuxPfzXW
BcVf345gLbprKNlXn/CWNaovFPKc2PAe4vnNwDvDzGHwf04jMQ==
=i8oJ
—–END PGP SIGNATURE—–


