Impact
The Post SMTP WordPress plugin has a stored cross‑site scripting flaw caused by insufficient sanitization of the user_email parameter. An attacker can submit an email address containing numeric HTML character references, which the plugin records verbatim in a failed‑send exception message. When a user later views the log entry page, the malicious script executes in the browser, allowing injection of arbitrary JavaScript. This can lead to session hijacking, credential theft, or page defacement for any visitor who triggers the log view.
Affected Systems
The vulnerability affects the Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App WordPress plugin for all releases up to and including version 4.0.1. Multisite WordPress installations with public registration enabled are able to trigger the flaw, as the plugin does not reject email addresses with encoded characters during the registration process.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and while EPSS data is not available, the vulnerability is not listed in the CISA KEV catalog. No authentication is required; an attacker only needs to provide a crafted email address during the registration phase. Once the payload is logged, every user who opens the log page is exposed to persistent, site‑wide cross‑site scripting.
OpenCVE Enrichment