The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether your WordPress site uses “post smtp” (Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App) and note the installed version.
If the version is 3.6.0 or earlier, treat the site as exposed because attackers can read email logs without authentication.
Upgrade Post SMTP to a version that includes the authorization fix (the vendor fix is referenced in the PostmanEmailLogs.php change around the 3386160 changeset; verify your upgrade includes that fix).
After upgrading, review Post SMTP email log storage and access controls, and rotate any credentials that might have been reset using exposed links.
The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to read arbitrary logged emails sent through the Post SMTP plugin, including password reset emails containing password reset links, which can lead to account takeover.
In plain language
Written by AI from the record
Post SMTP (WordPress) lets outsiders read your email logs without logging in (including password reset emails) if you’re on 3.6.0 or older—this is a serious account-hijacking risk for a typical small business.
Unauthenticated attacker can bypass a missing authorization (missing capability check on the plugin __construct) to disclose Post SMTP email logs over the network; if password reset emails are present, this enables account takeover.
If you're affected
Account takeover via reset links
Password reset link disclosure
Email confidentiality breach
Service disruption from locked accounts
What is it
This vulnerability lets an attacker see internal email “receipts” stored by the Post SMTP plugin. Those logs can include password reset emails, which contain the special reset links—so an attacker may use them to take over user accounts.
Who is affected
This matters if you run a WordPress site with the Post SMTP plugin (Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App) at version 3.6.0 or earlier. It’s a network risk without any login, and it’s reachable in the default configuration. The danger is highest when your site has password reset emails stored in Post SMTP logs (so an attacker can reuse the reset links).
How urgent is it
This is RED because the issue allows unauthenticated attackers to steal sensitive email logs, including password reset links, which can directly lead to account takeover. The risk is reachable by outsiders and does not require login. Treat this as urgent to fix immediately, especially if your site processes password resets or stores them in Post SMTP logs.
What to do — in detail
Confirm exposure
Identify the exact plugin name used on your WordPress site: “post smtp” (Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App).
Check the installed plugin version.
If it is 3.6.0 or earlier, assume the site is exposed because the missing authorization allows log disclosure without authentication over the network.
Assess whether sensitive data is present
In the Post SMTP setup/logs, look for evidence that the plugin stored emails related to password resets.
Review your recent account activity: any unexpected password reset requests or new logins since the time window when logs may have been collected.
Fix (upgrade)
Upgrade Post SMTP to a version that includes the vendor authorization fix referenced by the changeset/patch described by the vendor guidance (the fix is linked via changeset 3386160 and PostmanEmailLogs.php in the vendor references).
After upgrading, confirm the plugin update completed successfully and that the version is no longer 3.6.0 or earlier.
Contain and recover
If you suspect any password reset links were exposed or used: force a password reset for affected accounts and invalidate sessions/tokens where your WordPress setup allows it.
Rotate credentials for any administrators/users whose accounts might have been targeted.
Consider reviewing how long logs are retained and who can access them internally.
Monitor
Watch for unusual login patterns and repeated password reset requests.
Keep an eye on Post SMTP logs and access attempts to detect abnormal retrieval behavior.
CISA due date
No CISA KEV entry was provided in the findings, so no specific KEV-driven due date is known from this dataset.
Technical context
Severity and why it matters: The finding indicates a critical, unauthenticated information disclosure that can directly enable account takeover when password reset links are included in Post SMTP email logs.
Mechanism: A missing permission/capability check on the plugin’s __construct function allows attackers to read arbitrary logged emails through Post SMTP without logging in. Because password reset emails can contain usable reset links, the attacker can hijack user accounts.
Attack vector and reachability: Network-reachable in default configuration; authentication is not required; user interaction is not required.
Exploitation status: No CISA KEV listing was provided, and the exploit section contains only detection-template information (no explicit “in-the-wild exploitation” claim in the provided findings). However, the traffic-light verdict is RED, and the risk is severe given the direct account-takeover path.
EPSS: A predicted likelihood is provided in the findings (rising trend), but per instructions the public-facing blocks must not rely on EPSS for certainty when exploitation is confirmed via KEV/news; KEV is not listed here.
CWE: CWE-862 (Missing Authorization).
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.
saadiqbalindividual-devaka advanced file manager – ultimate file manager for wordpress and document library solution, points management system for gamification, ranks, badges, and loyalty rewards program – mycred, post smtp – complete email deliverability and smtp solution with email logs, alerts, backup smtp & mobile app