logo

Hackers exploit WordPress plugin Post SMTP to hijack admin accounts

ID: 3636cb0a-9189-59f3-b707-d10875cab84a

STIX ID: report--3636cb0a-9189-59f3-b707-d10875cab84a

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-11-04

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Post SMTP critical vulnerability (CVE-2025-11833) enables unauthenticated disclosure of email logs and admin account takeover; a patch is available but hundreds of thousands of sites remain at risk and active exploitation has been observed.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.