{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/post-smtp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:post-smtp:post-smtp:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-75962"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP \u0026 Mobile App"],"_cs_severities":["high"],"_cs_tags":["xss","web-application","wordpress","cve-2026-75962"],"_cs_type":"advisory","_cs_vendors":["Post SMTP"],"content_html":"\u003cp\u003eThe Post SMTP - Complete Email Deliverability and SMTP Solution plugin (up to version 4.0.1) contains a stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from insufficient input sanitization and output escaping within the plugin's error handling mechanism. Specifically, on WordPress Multisite installations with public registration enabled, the plugin fails to properly handle numeric HTML character references in email addresses. When an attacker provides a maliciously crafted email address during registration, the plugin persists this data verbatim into the email logs via failed-send exception messages. Because the plugin does not properly escape this data when rendering the logs, the attacker-supplied script executes whenever an administrator or authorized user views the email logs. This vulnerability allows for unauthorized actions within the WordPress dashboard, potentially leading to privilege escalation or further compromise of the WordPress site.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the victim's browser session. This can be used to steal session cookies, perform unauthorized administrative actions, or redirect users. The impact is significant for WordPress Multisite administrators who rely on the Post SMTP plugin for email logging, as they are the primary targets when viewing the compromised logs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching the affected plugin to version 4.0.2 or later once available. If patching is not immediately feasible, restrict public access to registration pages on WordPress Multisite installations to mitigate the unauthenticated attack vector.\u003c/p\u003e\n","date_modified":"2026-10-06T08:53:50Z","date_published":"2026-10-06T08:53:50Z","id":"https://feed.craftedsignal.io/briefs/2026-10-post-smtp-xss/","summary":"The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the user_email parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative log views.","title":"Stored XSS in Post SMTP WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-post-smtp-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Post SMTP","version":"https://jsonfeed.org/version/1.1"}