Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Post SMTP plugin defect exposes 200K WordPress sites to kidnap
    Security

    Post SMTP plugin defect exposes 200K WordPress sites to kidnap

    PineapplesUpdateBy PineapplesUpdateJuly 26, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Post SMTP plugin defect exposes 200K WordPress sites to kidnap
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Post SMTP plugin defect exposes 200K WordPress sites to kidnap

    More than 200,000 WordPress websites are using a weak version of the post SMTP plugin that allows hackers to control the administrator account.

    Post is a popular email delivery plugin for SMTP WordPress that counts more than 400,000 active installations. This is marketed as a replacement of default ‘wp_mail ()The function that is more reliable and convenient-rich.

    On 23 May, a security researcher reported vulnerability to WordPress Security Firm Patchstack. The defect is now identified as the CVE-2025-24000 and has received a moderate severity score of 8.8.

    The safety issue affects all versions of the post SMTP up to 3.2.0 and is due to a broken access control mechanism in the Rest API Endpoints of the plugin, which only verify that if a user was logged in, without checking their permission level.

    This means that low-privileged users, such as customers, can access email logs with full email material.

    On weak sites, a customer can start a password reset for a administrator account, intercepting the reset email through the log, and can get the account control.

    Weak code
    Weak code
    Source: Patchstack

    The developer of the plugin, Saad Iqbal, was informed about the blame and responded with a fix for the patchstack to review on 26 May.

    The solution ‘Get_logs_permission’ function was to include additional privilege checks that would validate the user permissions before giving access to sensitive API calls.

    The fix was included in the Post SMTP version 3.3.0, which was published on 11 June.

    Download the figures on WordPress.org Show that less than half of the plugin’s user base (48.5%) has updated at version 3.3. This means that more than 200,000 websites are unsafe for CVE-2025-24000.

    A notable 24.2%, corresponding to 96,800 sites, still runs the post SMTP version from the 2.x branch, which is unsafe for additional safety flaws, causing them to open to attacks.


    Knowledgeable

    CISOS knows how to purchase a board begins with a clear, strategic approach how the cloud safety runs the business price.

    This helps to introduce the risk, impact and priorities to the free, editable board report deck deck security leaders in clear business terms. Convert security updates into meaningful conversations and take fast decision in boardroom.

    200K defect exposes kidnap Plugin post sites SMTP WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘Happy Gilmore 2’ Ultimate Cameo Guide – Haley Joel Ocement to Post Malon
    Next Article Team Fort 2 is promoted on the steam chart with a summer update, including a group of community works.
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Security

    American Airlines subsidiary Envoy confirms Oracle data breach attack

    October 18, 2025
    Security

    Government considers destroying its data hub after decade-long intrusion

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.