Stored XSS Vulnerability in Post SMTP Plugin for WordPress
CVE-2026-75962
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 October 2026
What is CVE-2026-75962?
The Post SMTP plugin for WordPress is susceptible to stored cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping related to the 'user_email' parameter. This flaw allows unauthenticated attackers to inject malicious web scripts, which can execute when users access affected pages. The issue is particularly concerning in WordPress Multisite installations where public registration is enabled, as certain email address formats bypass stricter validation, allowing an attacker-controlled email to persist in logs through failed-send exception messages. Users are urged to update to version 4.0.2 or later to mitigate this risk.
Affected Version(s)
Post SMTP β Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App 0 <= 4.0.1