Authorization Bypass in Post SMTP Plugin for WordPress
CVE-2025-12887
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 December 2025
What is CVE-2025-12887?
The Post SMTP plugin for WordPress contains a vulnerability that allows unauthorized access to the OAuth credential management functionalities. Specifically, the 'handle_gmail_oauth_redirect' function fails to properly verify the authority of users attempting to update OAuth tokens. This oversight permits authenticated users with a minimum subscriber role to exploit the weakness and inject unauthorized or malicious OAuth credentials, posing significant security risks to WordPress sites utilizing this plugin.
Affected Version(s)
Post SMTP β Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App * <= 3.6.1