A critical vulnerability in the Post SMTP WordPress plugin allows attackers to take full control of compromised websites by exploiting broken access control. Many websites remain vulnerable despite a patch being released, highlighting the importance of timely updates. #PostSMTP #CVE-2025-24000
Keypoints
- The Post SMTP plugin is used on over 400,000 WordPress websites for email delivery.
- The vulnerability (CVE-2025-24000) allows any registered user to access sensitive data and email logs.
- Exploiting the flaw can enable attackers to reset passwords and take full website control.
- Developers patched the issue with version 3.3, released in June, but many sites remain unupdated.
- Maintaining plugin updates is crucial to prevent exploitation of known vulnerabilities.