Description
The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin not properly verifying that a user is authorized to update OAuth tokens on the 'handle_gmail_oauth_redirect' function. This makes it possible for authenticated attackers, with subscriber level access and above, to inject invalid or attacker-controlled OAuth credentials.
Problem types
Product status
* (semver)
Timeline
| 2025-11-01: | Discovered |
| 2025-11-07: | Vendor Notified |
| 2025-12-03: | Disclosed |
Credits
M Indra Purnama
References
www.wordfence.com/...-99e1-4dc2-855d-90339c2e24da?source=cve