The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the user_email parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative log views.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
xss
web-application
wordpress
cve-2026-75962
1t
1c