The dangerous wordpress plugin puts more than 160,000 sites in danger – here is what we know


  • The old versions of Post SMTP allowed the hackers to read all the emails
  • They could also reset the administrator’s password and read the notification email, access the account
  • More than 160,000 WordPress sites run the vulnerable version

A popular WordPress plugin with hundreds of thousands of active facilities has brought a vulnerability that allowed threat actors to take up compromise websites, experts warned.

The plugin is called Post SMTP, a tool that replaces WordPress’s default messaging function with an authenticated SMTP method, and currently has more than 400,000 active installations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top