Hackers exploit WordPress plugin Post SMTP to hijack admin accounts
ID: 3636cb0a-9189-59f3-b707-d10875cab84a
STIX ID: report--3636cb0a-9189-59f3-b707-d10875cab84a
Feed Name: Bleeping Computer
Threat Score
**Post SMTP critical vulnerability (CVE-2025-11833) enables unauthenticated disclosure of email logs and admin account takeover; a patch is available but hundreds of thousands of sites remain at risk and active exploitation has been observed.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
