Dangerous WordPress plugin puts over 160,000 sites at risk – here’s what we know

xwpEUtGigAH5K4krGZFy5K 1280 80


  • Older versions of Post SMTP allowed hackers to read all emails
  • They could also reset the admin password and read the notification email, gaining access to the account
  • More than 160,000 WordPress sites are running the vulnerable version

A popular WordPress plugin with hundreds of thousands of active installations carried a vulnerability that allowed threat actors to take over compromised websites, experts have warned.

The plugin is called Post SMTP, a tool that replaces WordPress’s default email function with an authenticated SMTP method, and currently counts more than 400,000 active installations.

Share this post:

Leave a Reply

Your email address will not be published. Required fields are marked *

From the latest gadgets to expert reviews and unbeatable deals — dive into our handpicked content across all things tech.