Executive brief
SmartSMTP is a WordPress plugin used for email functionality on websites. An unauthenticated attacker can inject malicious scripts into affected sites through cross-site scripting (XSS), allowing them to steal visitor data, hijack accounts, or compromise website visitors without requiring the attacker to have admin access.
Technical details
This is a stored or reflected cross-site scripting (XSS) vulnerability in the SmartSMTP WordPress plugin affecting versions 1.2.0 and earlier. The vulnerability requires an unauthenticated attacker to craft a malicious input, but successful exploitation requires user interaction (e.g., a privileged user clicking a malicious link or visiting a crafted page). The attacker can inject arbitrary JavaScript that executes in victims' browsers, enabling data theft or account hijacking. A patch is available in version 1.2.1 and later.
Affected products
- ThemeGrill SmartSMTP <=1.2.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Version 1.2.1 or later available