CyberzSOC

Publication detail
← Back to advisories & guidance

2024-011: Vulnerability in Wordpress POST SMTP Mailer Plugin ↗ source

January 19, 2024 CERT-EU Advisory

Summary

This vulnerability, identified as CVE-2023-6875 (CVSS score of 9.8)[1], may allow an unauthenticated attacker to reset the API key used to authenticate to the mailer and view logs, including password reset emails on WordPress sites that use this plugin [2]. This vulnerability could affect sites that have the POST SMTP Mailer plugin installed and configured, which is estimated to be over 300,000 sites [3]. The POST SMTP Mailer plugin for WordPress is vulnerable to unauthorised access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing website takeover. “POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP” Wordpress plugin version 2.8.7 and below. It is also advised to monitor their WordPress sites for any signs of unauthorised changes, such as injected scripts or deleted directories.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-6875 9.8 Critical wpexpertsio POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.