Stored XSS Vulnerability in Post SMTP Plugin for WordPress
CVE-2026-75962

7.2HIGH

What is CVE-2026-75962?

The Post SMTP plugin for WordPress is susceptible to stored cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping related to the 'user_email' parameter. This flaw allows unauthenticated attackers to inject malicious web scripts, which can execute when users access affected pages. The issue is particularly concerning in WordPress Multisite installations where public registration is enabled, as certain email address formats bypass stricter validation, allowing an attacker-controlled email to persist in logs through failed-send exception messages. Users are urged to update to version 4.0.2 or later to mitigate this risk.

Affected Version(s)

Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App 0 <= 4.0.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Brunner
.