CVE-2025-12887: falha de média gravidade em saadiqbal Post SMTP – Complete Email…
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.4epss 0.3%
probabilidade de exploração
0.3%top 81% das CVEs
exploração observada
nãonenhuma fonte reporta
The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it possible for authenticated attackers, with subscriber level access and above, to inject invalid or attacker-controlled OAuth credentials. CVE-2025-67563 appears to be a duplicate of this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Produtos afetados
saadiqbal · Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile AppCVEs relacionadas — saadiqbal Post SMTP – Complete Email…
No mesmo produto, das mais perigosas para as menos.
CVE-2023-6875CRITICALPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app APIEPSS 90.3%CVE-2025-11833CRITICALPost SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log DisclosureEPSS 61.5%CVE-2023-7027HIGHPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via deviceEPSS 0.9%CVE-2021-4422MEDIUMPOST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery BypassEPSS 0.5%CVE-2023-3082HIGHPost SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via EmailEPSS 0.5%CVE-2024-5207HIGHPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL InjectionEPSS 0.5%