A critical vulnerability in the popular WordPress plugin Post SMTP has been exploited by hackers to hijack administrator accounts, posing a significant security risk to websites using this plugin. The flaw allows attackers to escalate privileges and gain unauthorized access to sensitive administrative functions, potentially leading to full site takeover. This exploitation highlights the importance of timely updates and vigilant security practices for WordPress site administrators. The Post SMTP plugin, widely used for email delivery, became a target due to its vulnerability that was not patched promptly, enabling attackers to leverage it for malicious purposes. Website owners are urged to update to the latest plugin version immediately and review their security configurations to prevent exploitation. This incident underscores the ongoing threats facing WordPress ecosystems and the need for continuous monitoring and rapid response to vulnerabilities.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 04 Nov 2025 21:50:15 +0000