Skip to main content
Vulnerability Database/CVE-2025-12887

CVE-2025-12887: Post SMTP WordPress Auth Bypass Flaw

CVE-2025-12887 is an authorization bypass flaw in the Post SMTP WordPress plugin allowing authenticated attackers to inject malicious OAuth credentials. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-12887 Overview

CVE-2025-12887 is an authorization bypass vulnerability in the Post SMTP plugin for WordPress. The flaw affects all versions up to and including 3.6.1. The handle_gmail_oauth_redirect function fails to verify that the requesting user is authorized to update OAuth tokens. Authenticated attackers with subscriber-level access or above can inject invalid or attacker-controlled OAuth credentials into the plugin configuration. The vulnerability is classified under [CWE-862: Missing Authorization]. CVE-2025-67563 appears to be a duplicate of this issue.

Critical Impact

Low-privileged WordPress users can hijack the plugin's Gmail OAuth configuration, redirecting outbound mail authentication to attacker-controlled credentials and disrupting site email delivery.

Affected Products

  • Post SMTP plugin for WordPress, all versions through 3.6.1
  • WordPress sites using Gmail OAuth integration via Post SMTP
  • WordPress installations permitting subscriber-level account registration

Discovery Timeline

  • 2025-12-03 - CVE-2025-12887 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-12887

Vulnerability Analysis

The Post SMTP plugin exposes an OAuth redirect handler used to complete the Gmail authorization flow. The plugin stores the returned OAuth tokens so the site can send mail via Gmail's authenticated API. The handle_gmail_oauth_redirect function processes this callback but does not enforce a capability check on the current user. Any authenticated user, including a subscriber, can invoke the handler and cause the plugin to persist OAuth credentials of their choosing.

Once attacker-controlled or invalid credentials are stored, the plugin's outbound mail configuration is compromised. This can break password reset messages, order confirmations, and notification email, or route authentication artifacts through an attacker-controlled endpoint. The issue does not permit direct code execution, but it undermines integrity and availability of a security-adjacent function.

Root Cause

The root cause is missing authorization enforcement in the OAuth redirect handler. The function relies on the presence of a valid OAuth callback rather than validating the initiating user's WordPress capabilities. There is no current_user_can('manage_options') gate protecting the token update path, and no state binding tying the OAuth callback to an administrator-initiated flow.

Attack Vector

Exploitation requires an authenticated WordPress account at subscriber level or above, which is trivial on sites that allow open registration. The attacker crafts a request to the plugin's OAuth redirect endpoint carrying OAuth response parameters. The plugin accepts the request and overwrites the stored Gmail OAuth token configuration. No user interaction from an administrator is required. Refer to the Wordfence Vulnerability Report for additional technical context.

Detection Methods for CVE-2025-12887

Indicators of Compromise

  • Unexpected changes to Post SMTP Gmail OAuth configuration or client credentials in the WordPress options table.
  • HTTP requests to the plugin's handle_gmail_oauth_redirect endpoint originating from non-administrator sessions.
  • Sudden failures of outbound email delivery or password reset messages after subscriber account activity.
  • New or unfamiliar subscriber account registrations followed by requests to Post SMTP administrative endpoints.

Detection Strategies

  • Review WordPress access logs for requests to Post SMTP OAuth callback URLs correlated with low-privileged user session cookies.
  • Audit the wp_options table for modifications to Post SMTP configuration entries with timestamps outside administrator activity windows.
  • Compare stored Gmail OAuth client_id values against the values configured by administrators to detect substitution.

Monitoring Recommendations

  • Alert on any change to Post SMTP configuration options in production WordPress sites.
  • Monitor SMTP send failures and Gmail API authentication errors as early signals of tampered credentials.
  • Track subscriber-level account activity that touches plugin administrative endpoints.

How to Mitigate CVE-2025-12887

Immediate Actions Required

  • Update the Post SMTP plugin to a version later than 3.6.1 that includes the fix from WordPress changeset 3402203.
  • Rotate the Gmail OAuth client secret and re-authorize the plugin from an administrator account after patching.
  • Audit existing WordPress user accounts and remove unnecessary subscriber-level accounts.
  • Verify that the Post SMTP Gmail configuration still points to the intended client_id.

Patch Information

The upstream fix is published in WordPress plugin changeset 3402203, which adds authorization enforcement to the Gmail OAuth redirect handler. Site operators should install the patched Post SMTP release from the WordPress plugin repository.

Workarounds

  • Disable open user registration by unsetting the users_can_register option until the plugin is updated.
  • Deactivate the Post SMTP plugin and revert to an alternate mail transport if patching is delayed.
  • Restrict access to the plugin's OAuth callback URL at the web server or WAF layer to administrator IP ranges.
bash
# Example WordPress CLI commands to reduce exposure
wp option update users_can_register 0
wp plugin update post-smtp
wp user list --role=subscriber --field=ID

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.