Executive brief
The Gmail SMTP plugin for WordPress, which allows websites to send emails via Gmail, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By convincing a logged-in user to click a malicious link, an attacker could potentially modify plugin settings or disrupt email delivery services. This could lead to unauthorized configuration changes or the interruption of automated site communications.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Gmail SMTP plugin for WordPress (versions 1.2.3.19 and below) due to insufficient validation of request origins. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a privileged user (such as an administrator) into executing it while authenticated. Successful exploitation allows the attacker to perform actions on behalf of the user, such as modifying SMTP configuration settings, without their knowledge. The issue is resolved in version 1.2.3.20.
Affected products
- Noor Alam Gmail SMTP <= 1.2.3.19
Timeline
- 2026-06-10: other: Reported by researcher Ananda Dhakal
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Version 1.2.3.20 released to address the vulnerability