Authorization Bypass in Post SMTP Plugin for WordPress
CVE-2025-12887

5.4MEDIUM

What is CVE-2025-12887?

The Post SMTP plugin for WordPress contains a vulnerability that allows unauthorized access to the OAuth credential management functionalities. Specifically, the 'handle_gmail_oauth_redirect' function fails to properly verify the authority of users attempting to update OAuth tokens. This oversight permits authenticated users with a minimum subscriber role to exploit the weakness and inject unauthorized or malicious OAuth credentials, posing significant security risks to WordPress sites utilizing this plugin.

Affected Version(s)

Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App * <= 3.6.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

M Indra Purnama
.