Cross-Site Scripting
10 records38.5%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 26 vulnerability records associated with Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App, published between 2021 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2021 | 1 | |
| 2022 | 2 | |
| 2023 | 7 | |
| 2024 | 5 | |
| 2025 | 7 | |
| 2026 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 2 | 7.7% |
| High | 10 | 38.5% |
| Medium | 14 | 53.8% |
First: 2022. Latest: 2026.
First: 2024. Latest: 2026.
First: 2023. Latest: 2025.
First: 2021. Latest: 2023.
First: 2022. Latest: 2022.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.6.33.9.03.6.23.6.13.4.23.3.03.1.33.1.02.9.122.9.102.9.42.8.82.8.72.7.12.6.12.5.9-beta.12.5.82.5.72.1.72.1.42.0.21Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.6.2 | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App <= 3.6.2 - Unauthenticated Stored Cross-Site Scripting | May 28, 2026 | 3.6.3 | High |
*-3.0.0 | Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter | April 30, 2026 | 3.1.0 | Medium |
*-3.8.0 | Post SMTP <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'event_type' | March 17, 2026 | 3.9.0 | High |
*-3.8.0 | Post SMTP <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Office 365 OAuth Configuration Overwrite | March 17, 2026 | 3.9.0 | Medium |
*-3.6.1 | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update | December 3, 2025 | 3.6.2 | Medium |
*-3.6.0 | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure | October 31, 2025 | 3.6.1 | Critical |
*-3.4.1 | Post SMTP <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update | September 2, 2025 | 3.4.2 | Medium |
*-3.2.0 | Post SMTP <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via Email Log Exposure | July 21, 2025 | 3.3.0 | High |
*-3.1.2 | Post SMTP <= 3.1.2 - Authenticated (Administrator+) SQL Injection via columns Parameter | March 7, 2025 | 3.1.3 | Medium |
*-3.0.2 | Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting | February 17, 2025 | 3.1.0 | High |
*-2.9.11 | Post SMTP <= 2.9.11 - Missing Authorization via regenerate_qrcode() | January 7, 2025 | 2.9.12 | Medium |
*-2.9.9 | Post SMTP <= 2.9.9 - Authenticated (Administrator+) SQL Injection | November 15, 2024 | 2.9.10 | Medium |
*-2.9.3 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection | May 22, 2024 | 2.9.4 | High |
*-2.8.7 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API | January 10, 2024 | 2.8.8 | Critical |
*-2.8.7 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via device | January 2, 2024 | 2.8.8 | High |
*-2.8.6 | POST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msg | January 2, 2024 | 2.8.7 | Medium |
*-2.8.6 | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.6 - Authenticated (Administrator+) SQL Injection | December 21, 2023 | 2.8.7 | High |
*-2.7.0 | POST SMTP Mailer <= 2.7.0 - Unauthenticated Stored Cross-Site Scripting | November 6, 2023 | 2.7.1 | High |
[*, 2.6.1) | Post SMTP <= 2.6.0 - Authenticated (Administrator+) SQL Injection | October 3, 2023 | 2.6.1 | High |
2.1.2-beta.1 - 2.5.7 | Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get | July 18, 2023 | 2.5.9-beta.1 | Medium |
*-2.5.7 | Post SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via Email | July 11, 2023 | 2.5.8 | High |
*-2.5.6 | POST SMTP Mailer <= 2.5.6 - Cross-Site Request Forgery to Arbitrary Log Deletion | June 26, 2023 | 2.5.7 | Medium |
*-2.5.6 | POST SMTP Mailer <= 2.5.6 - Cross-Site Request Forgery to Account Compromise | June 26, 2023 | 2.5.7 | Medium |
*-2.1.6 | Post SMTP <= 2.1.6 - Authenticated (Administrator+) Blind Server-Side Request Forgery | September 5, 2022 | 2.1.7 | Medium |
*-2.1.3 | Post SMTP Mailer/Email Log <= 2.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting | August 18, 2022 | 2.1.4 | Medium |
Selected source records
Published: May 28, 2026
Published: April 30, 2026
Published: March 17, 2026
Published: March 17, 2026
Published: December 3, 2025
Published: October 31, 2025
Published: September 2, 2025
Published: July 21, 2025
Published: October 31, 2025
Published: January 10, 2024
Published: July 21, 2025
Published: May 22, 2024
Published: February 17, 2025
Published: October 3, 2023
Published: March 17, 2026
Published: July 11, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.