Description
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSMTP fluent-smtp allows Cross Site Request Forgery.This issue affects FluentSMTP: from n/a through <= 2.2.80.
Published: 2025-01-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw in the Shahjahan Jewel FluentSMTP WordPress plugin that allows an attacker to forge requests sent by an authenticated user; the description does not specify the concrete operations that could be performed but the lack of CSRF safeguards means any action the plugin accepts could be invoked without the user’s intent.

Affected Systems

All installations of the Shahjahan Jewel "FluentSMTP" plugin for WordPress running version 2.2.80 or earlier are affected; there are no other vendors or products listed as impacted.

Risk and Exploitability

The CVSS score of 4.3 points to a low to moderate severity, and the EPSS rating of < 1% indicates a very low probability of exploitation at present; the vulnerability is not in the CISA KEV catalog. Attackers would need a victim who is authenticated to WordPress and to visit a crafted URL or submit a forged form to trigger the flaw. Based on the CSRF nature of the vulnerability, it is inferred that the attack requires an authenticated user to be tricked into interacting with a malicious URL or form.

Generated by OpenCVE AI on May 2, 2026 at 11:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the FluentSMTP plugin to version 2.2.81 or later.
  • If an immediate upgrade is not possible, temporarily disable the plugin or its email‑sending capabilities until the update is applied.
  • After applying the update, review the plugin settings to ensure no unintended configuration changes were made.

Generated by OpenCVE AI on May 2, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3929 Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.
History

Fri, 24 Apr 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80. Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSMTP fluent-smtp allows Cross Site Request Forgery.This issue affects FluentSMTP: from n/a through <= 2.2.80.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.
Title WordPress FluentSMTP plugin <= 2.2.80 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:33.705Z

Reserved: 2025-01-23T14:52:51.692Z

Link: CVE-2025-24739

cve-icon Vulnrichment

Updated: 2025-01-24T18:28:24.253Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:48.177

Modified: 2026-06-17T08:59:31.703

Link: CVE-2025-24739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T11:30:41Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)