Junglewise Threat Intelligence

CVE-2026-81278: WPExperts Post SMTP missing authorization in settings management

CVE-2026-81278 · Severity: medium · CVSS 5.4 · Published 2026-08-31

Executive brief

Post SMTP is a WordPress plugin for email delivery and SMTP configuration. A missing authorization vulnerability allows users with low-level subscriber privileges to change critical site settings including security configurations, potentially disabling security features or locking out administrators.

Technical details

The vulnerability is a broken access control issue (OWASP A1) in Post SMTP versions 4.0.0 through beta.1. The plugin fails to properly validate user permissions before allowing settings changes, permitting a subscriber-level authenticated user to modify sensitive plugin and site configurations. The attack requires a valid WordPress user account with subscriber or higher privileges. An attacker can alter email settings, disable security features, or modify plugin behavior without proper authorization checks. The issue has been patched in version 4.0.1.

Affected products

  • WPExperts Post SMTP 4.0.0 through beta.1

Timeline

  • 2026-08-24: disclosed: Reported by mad4cyber
  • 2026-08-26: advisory: Published by Patchstack
  • 2026-08-26: patched: Fixed in version 4.0.1

References

Related threats