| CVE-2025-22800 | WordPress Post SMTP plugin <= 2.9.11 - Broken Access Control vulnerability | Saad Iqbal | Post SMTP | Medium | 4.3 | 2025-01-13 13:11:37 | Deep Dive |
| CVE-2024-56003 | WordPress Caldera SMTP Mailer plugin <= 1.0.1 - Broken Access Control vulnerability | David Cramer | Caldera SMTP Mailer | Medium | 4.3 | 2024-12-16 15:54:56 | Deep Dive |
| CVE-2023-48332 | WordPress Mail Bank – #1 Mail SMTP Plugin for WordPress plugin <= 4.0.14 - Broken Access Control vulnerability | Varun Sharma | Mail Bank - #1 Mail SMTP Plugin for WordPress | 中危 | - | 2024-12-09 11:30:28 | Deep Dive |
| CVE-2024-9511 | FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider <= 2.2.82 - Unauthenticated PHP Object Injection | techjewel | FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider | Critical | 9.8 | 2024-11-23 07:38:06 | Deep Dive |
| CVE-2024-52436 | WordPress Post SMTP plugin <= 2.9.9 - SQL Injection vulnerability | Saad Iqbal | Post SMTP | High | 7.6 | 2024-11-18 14:30:21 | Deep Dive |
| CVE-2024-50530 | WordPress Stars SMTP Mailer plugin <= 2.2.1 - Arbitrary File Upload vulnerability | Myriad Solutionz | Stars SMTP Mailer | Critical | 9.9 | 2024-11-04 13:40:41 | Deep Dive |
| CVE-2024-8477 | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cross-Site Request Forgery | neeraj_slit | Brevo – Email, SMS, Web Push, Chat, and more. | Medium | 4.3 | 2024-10-10 02:06:12 | Deep Dive |
| CVE-2024-43287 | WordPress Brevo plugin <= 3.1.82 - Cross Site Request Forgery (CSRF) vulnerability | Brevo | Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue | Medium | 4.3 | 2024-08-26 20:46:07 | Deep Dive |
| CVE-2024-6694 | WP Mail SMTP <= 4.0.1 - Authenticated (Admin+) SMTP Password Exposure | smub | WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin | Low | 2.7 | 2024-07-20 03:20:32 | Deep Dive |
| CVE-2024-3073 | Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UI | smub | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more | Low | 2.7 | 2024-06-13 08:31:31 | Deep Dive |
| CVE-2023-52233 | WordPress POST SMTP Mailer plugin <= 2.8.6 - Broken Access Control on API vulnerability | Post SMTP | Post SMTP Mailer/Email Log | High | 8.6 | 2024-06-11 16:05:39 | Deep Dive |
| CVE-2024-35668 | WordPress Newsletter, SMTP, Email marketing and Subscribe forms by Brevo plugin <= 3.1.77 - Reflected Cross Site Scripting (XSS) vulnerability | Brevo | Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue | High | 7.1 | 2024-06-04 13:48:46 | Deep Dive |
| CVE-2024-5207 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | High | 7.2 | 2024-05-30 05:33:15 | Deep Dive |
| CVE-2024-1789 | WordPress plugin WP SMTP 安全漏洞 | jack-kitterhing | WP SMTP | High | 7.2 | 2024-04-26 08:29:21 | Deep Dive |
| CVE-2024-29128 | WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerability | Post SMTP | POST SMTP | High | 7.1 | 2024-03-19 14:04:00 | Deep Dive |
| CVE-2024-27192 | WordPress Configure SMTP Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) | Scott Reilly | Configure SMTP | High | 7.1 | 2024-03-15 12:44:31 | Deep Dive |
| CVE-2024-25914 | WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF) | Photoboxone | SMTP Mail | Medium | 4.3 | 2024-02-13 05:04:28 | Deep Dive |
| CVE-2023-3178 | POST SMTP Mailer < 2.5.7 - Arbitrary Log Deletion via CSRF | Unknown | POST SMTP Mailer | 中危 | - | 2024-01-16 15:55:30 | Deep Dive |
| CVE-2023-6620 | Post SMTP < 2.8.7 - Admin+ SQL Injection | Unknown | POST SMTP Mailer | 高危 | - | 2024-01-15 15:10:41 | Deep Dive |
| CVE-2023-6875 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Critical | 9.8 | 2024-01-11 08:33:06 | Deep Dive |