Description
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message.
Published: 2026-10-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Post SMTP WordPress plugin has a stored cross‑site scripting flaw caused by insufficient sanitization of the user_email parameter. An attacker can submit an email address containing numeric HTML character references, which the plugin records verbatim in a failed‑send exception message. When a user later views the log entry page, the malicious script executes in the browser, allowing injection of arbitrary JavaScript. This can lead to session hijacking, credential theft, or page defacement for any visitor who triggers the log view.

Affected Systems

The vulnerability affects the Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App WordPress plugin for all releases up to and including version 4.0.1. Multisite WordPress installations with public registration enabled are able to trigger the flaw, as the plugin does not reject email addresses with encoded characters during the registration process.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, and while EPSS data is not available, the vulnerability is not listed in the CISA KEV catalog. No authentication is required; an attacker only needs to provide a crafted email address during the registration phase. Once the payload is logged, every user who opens the log page is exposed to persistent, site‑wide cross‑site scripting.

Generated by OpenCVE AI on October 6, 2026 at 06:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Post SMTP to version 4.0.2 or later, which removes the flawed input handling.
  • If an upgrade cannot be applied immediately, disable public registration on the multisite network or implement a manual approval workflow to prevent unverified email submissions.
  • Clear existing email log entries that contain suspicious HTML character references before applying the patch, ensuring no malicious script is stored for execution.

Generated by OpenCVE AI on October 6, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable without authentication on WordPress Multisite installations with public registration enabled, as WordPress accepts email addresses containing numeric HTML character references that Post SMTP's stricter validator rejects, persisting the attacker-controlled address verbatim to the email log via the failed-send exception message.
Title Post SMTP <= 4.0.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_email' Parameter (Multisite Registration → Failed Email Log)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-06T05:30:46.124Z

Reserved: 2026-08-18T16:38:04.430Z

Link: CVE-2026-75962

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:01.687

Modified: 2026-10-06T06:17:01.687

Link: CVE-2026-75962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')