Loading HuntDB...

GHSA-9cw8-p5p2-35pf

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover.

Related CVEs

Key Information

GHSA ID
GHSA-9cw8-p5p2-35pf
Published
January 11, 2024 9:30 AM
Last Modified
June 3, 2025 3:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.