Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Post SMTP Bug Exposes 200K Sites

July 28, 2025
Reading Time: 2 mins read
in Alerts
Scattered Spider Hits ESXi Servers

A significant security flaw has been discovered in Post SMTP, a widely used WordPress plugin with over 400,000 active installations designed to enhance email reliability. The vulnerability, identified as CVE-2025-24000, carries a high-severity score of 8.8 and affects all versions of the plugin up to 3.2.0. With less than half of the user base having applied the necessary update, more than 200,000 websites currently remain exposed to attacks that could allow hackers to gain full administrative control.

The core of the issue lies in a broken access control mechanism within the plugin’s REST API. The vulnerable code correctly checked if a user was logged into the WordPress site but failed to verify their specific permission level. This oversight means that any authenticated user, including those with the lowest privileges like a “Subscriber,” could gain unauthorized access to sensitive functions, most notably the email logs which can contain the full content of all emails sent from the website.

A malicious actor can exploit this vulnerability with relative ease. By creating a low-level subscriber account on a target website, the attacker can initiate a password reset request for an administrator’s account. They can then use the access control flaw to view the site’s email logs, intercept the password reset email containing the unique reset link, and use it to set a new password. This simple process gives the attacker complete control over the administrator account and, consequently, the entire WordPress site. hijacking the high-privilege account, effectively taking control of the entire website.

Discovery and Patching Process

The vulnerability was responsibly disclosed to the WordPress security firm PatchStack on May 23. The plugin’s developer, Saad Iqbal, was promptly notified and responded with a fix for review just three days later, on May 26. The solution involved adding crucial privilege checks to the get_logs_permission function, ensuring that only authorized users can access the sensitive API endpoints. This fix was officially released to the public in Post SMTP version 3.3.0 on June 11.

Urgent Call to Update
Despite the availability of a patch, download statistics from WordPress.org show a concerningly slow adoption rate. Currently, only 48.5% of users have updated to the secure version, leaving over 200,000 sites vulnerable. Furthermore, a notable 24.2% of installations, equivalent to nearly 97,000 sites, are still running much older versions from the 2.x branch, which contain this and other security flaws. Administrators using the Post SMTP plugin are strongly urged to update to version 3.3.0 or newer without delay to protect their websites from this critical threat.

Reference:

  • Post SMTP Plugin Flaw Exposes 200K WordPress Sites to Potential Hijacking Attacks
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityJuly 2025
ADVERTISEMENT

Related Posts

China Hackers Breach Telecom Firm

China Hackers Breach Telecom Firm

October 24, 2025
China Hackers Breach Telecom Firm

Lazarus Hits European Defense Firms

October 24, 2025
China Hackers Breach Telecom Firm

YouTube Videos Used As Malware Traps

October 24, 2025
Gift Card Heist Via Cloud Hackers

Gift Card Heist Via Cloud Hackers

October 23, 2025
Gift Card Heist Via Cloud Hackers

Fake Zoom Calls Target Ukraine Aid

October 23, 2025
Gift Card Heist Via Cloud Hackers

MuddyWater Launches Global Spying

October 23, 2025

Latest Alerts

China Hackers Breach Telecom Firm

YouTube Videos Used As Malware Traps

Lazarus Hits European Defense Firms

Gift Card Heist Via Cloud Hackers

MuddyWater Launches Global Spying

Fake Zoom Calls Target Ukraine Aid

Subscribe to our newsletter

    Latest Incidents

    Hackers Breach Verstappen Data

    Toys R Us Canada Data Breach Alert

    Shaq Range Rover Stolen After Hack

    Ransomware Hits Jewett Cameron

    Salt Typhoon Hacks European Telecom

    JFL Loses 800K Weekly After Hack

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial