logo

Over 150k WordPress sites at takeover risk via vulnerable plugin

ID: 53ae6dd7-9ffa-5b04-a576-6ecad02c0a9f

STIX ID: report--53ae6dd7-9ffa-5b04-a576-6ecad02c0a9f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Two vulnerabilities in the POST SMTP Mailer WordPress plugin (CVE-2023-6875: unauthenticated authorization bypass via type-juggling; CVE-2023-7027: stored XSS) affected versions up to 2.8.7 and could allow full site takeover. Wordfence reported the issues and the vendor released a patched 2.8.8 on 2024-01-01; roughly 150,000 sites are estimated to remain vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.