QID 731078

Date Published: 2024-01-16

QID 731078: WordPress Plugin POST Simple Mail Transfer Protocol (SMTP) Authorization Bypass Vulnerability

Post SMTP is a free and next generation WordPress SMTP plugin that has everything you need to improve the email deliverability of your WordPress site.

CVE-2023-6875 : The POST SMTP Mailer Email log Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect app REST endpoint in all versions up to and including 2.8.7. Affected Versions: POST SMTP prior to 2.8.8

QID Detection Logic (Unauthenticated): This unauthenticated detection checks for installed vulnerable version for POST SMTP Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow an unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs including password reset emails allowing site takeover.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to POST SMTP Plugin version 2.8.8 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731078

    Software Advisories
    Advisory ID Software Component Link
    POST SMTP URL Logo wordpress.org/plugins/post-smtp/#developers