Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover 

Posted on November 5, 2025November 5, 2025 By CWS

A whole bunch of hundreds of internet sites could also be uncovered to account takeover assaults as a consequence of a critical-severity vulnerability within the electronic mail supply WordPress plugin Publish SMTP, Defiant warns.

A WordPress plugin with greater than 400,000 lively installations, Publish SMTP was designed to exchange a web site’s default PHP mail perform with an SMTP one. It supplies numerous options, together with electronic mail logging capabilities.

Publish SMTP variations as much as 3.6.0 lack a functionality verify in a selected perform, thus permitting unauthenticated attackers to learn arbitrary logged emails despatched utilizing the plugin.

As a result of the attacker can learn password reset emails despatched by way of Publish SMTP, they will take over any account on the web site, together with administrative accounts.

“This can be utilized for full web site compromise by an attacker triggering a password reset for a web site’s administrator person, after which acquiring the password reset electronic mail via the log information. As soon as an attacker has entry to this key, they will reset the password for that person and log in to the account,” Defiant notes.

The vulnerability is tracked as CVE-2025-11833 (CVSS rating of 9.8) and was resolved in Publish SMTP model 3.6.1, on October 29.

In keeping with Defiant, in-the-wild exploitation of the safety defect began roughly three days after patches have been launched. The WordPress safety agency has blocked over 4,500 assaults up to now.

“We urge customers to replace their websites with the newest patched model of Publish SMTP, model 3.6.1 on the time of this publication as quickly as potential as lively exploitation has already began and we anticipate the marketing campaign to choose up quickly,” Defiant notes.Commercial. Scroll to proceed studying.

Primarily based on WordPress’s statistics, Publish SMTP was downloaded lower than 200,000 instances over the previous seven days, which means that roughly 200,000 web sites are probably uncovered to takeover due to the bug.

The flaw was reported by a researcher named Netranger by way of the Wordfence Bug Bounty Program. The researcher was awarded a $7,800 bug bounty for the invention.

Associated: Yr-Outdated WordPress Plugin Flaws Exploited to Hack Web sites

Associated: Flaw Permitting Web site Takeover Present in WordPress Plugin With 400k Installations

Associated: Hackers Inject Malware Into Gravity Types WordPress Plugin

Associated: Forminator WordPress Plugin Vulnerability Exposes 400,000 Web sites to Takeover

Security Week News Tags:Exploited, Exposes, Flaw, Plugin, Post, Sites, SMTP, Takeover, WordPress

Post navigation

Previous Post: CISA Warns of Control Web Panel OS Command Injection Vulnerability Exploited in Attacks
Next Post: Securing the Open Android Ecosystem with Samsung Knox

Related Posts

Chinese Spies Target Networking and Virtualization Flaws to Breach Isolated Environments Security Week News
North Korean Hackers Have Stolen $2 Billion in Cryptocurrency in 2025 Security Week News
New ClickFix Malware Variant ‘LightPerlGirl’ Targets Users in Stealthy Hack Security Week News
High-Value NPM Developers Compromised in New Phishing Campaign Security Week News
Prison Sentence for Man Involved in SEC X Account Hack Security Week News
Australia’s TPG Telecom Investigating iiNet Hack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ConductorOne Raises $79 Million in Series B Funding
  • Securing the Open Android Ecosystem with Samsung Knox
  • Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover 
  • CISA Warns of Control Web Panel OS Command Injection Vulnerability Exploited in Attacks
  • Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ConductorOne Raises $79 Million in Series B Funding
  • Securing the Open Android Ecosystem with Samsung Knox
  • Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover 
  • CISA Warns of Control Web Panel OS Command Injection Vulnerability Exploited in Attacks
  • Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News