Skip to main content
Vulnerability Database/CVE-2026-75962

CVE-2026-75962: Post SMTP WordPress Plugin XSS Vulnerability

CVE-2026-75962 is a stored XSS flaw in the Post SMTP WordPress plugin allowing unauthenticated attackers to inject malicious scripts via email parameters. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-75962 Overview

CVE-2026-75962 is a Stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the Post SMTP plugin for WordPress. The flaw affects all versions up to and including 4.0.1. Attackers inject arbitrary web scripts through the user_email parameter due to insufficient input sanitization and output escaping. The injected payload persists in the plugin's email log and executes when an administrator views the affected page. On WordPress Multisite installations with public registration enabled, unauthenticated attackers can exploit the issue.

Critical Impact

Unauthenticated attackers can inject persistent JavaScript into the Post SMTP email log, executing in administrator browsers and enabling session theft or administrative account takeover on vulnerable Multisite installations.

Affected Products

  • Post SMTP – Complete Email Deliverability and SMTP Solution plugin for WordPress
  • All versions up to and including 4.0.1
  • WordPress Multisite installations with public registration enabled are directly exploitable without authentication

Discovery Timeline

  • 2026-10-06 - CVE-2026-75962 published to the National Vulnerability Database
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-75962

Vulnerability Analysis

The vulnerability stems from a validation mismatch between WordPress core and the Post SMTP plugin. WordPress accepts email addresses that contain numeric HTML character references. Post SMTP applies a stricter validator that rejects these addresses. When the plugin's send operation fails, the attacker-supplied address is written verbatim into the exception message. That message is then stored in the plugin's email log without sanitization or output escaping.

When an administrator opens the Post SMTP email log in wp-admin, the stored payload renders in the browser context. The script executes with the privileges of the viewing user. Because stored XSS persists across sessions, the payload fires repeatedly for every administrator who views the log.

Root Cause

The root cause is a trust boundary error between two validators. WordPress registration accepts an input that Post SMTP later rejects. The failed-send path logs the raw, attacker-controlled email string in the exception message. Neither the write path nor the read path applies sanitization helpers such as esc_html() or wp_kses(). The relevant log-writing logic is referenced in PostmanEmailLogService.php and PostmanWpMail.php.

Attack Vector

An unauthenticated attacker registers an account on a vulnerable WordPress Multisite with public registration enabled. The registration email contains a crafted payload using numeric HTML character references that bypasses WordPress validation. The plugin fails to send the welcome or notification email and logs the exception, embedding the attacker's payload directly in the stored log entry. When an administrator later views the Post SMTP log page, the JavaScript executes in their session.

The vulnerability mechanism is described in the Wordfence vulnerability report. No proof-of-concept code is published at this time.

Detection Methods for CVE-2026-75962

Indicators of Compromise

  • Email log entries in Post SMTP containing HTML tags, <script> elements, or numeric HTML character references such as &# sequences in the sender or recipient fields
  • Unexpected administrator account creations, role changes, or plugin installations following access to the Post SMTP email log
  • New user registrations on Multisite installations with malformed or encoded email addresses
  • Outbound requests from administrator browser sessions to unfamiliar domains while viewing wp-admin pages

Detection Strategies

  • Inspect the Post SMTP email log database table for entries containing <, >, script, onerror, onload, or encoded variants in the recipient address field
  • Audit the WordPress users and signups tables for user_email values containing non-standard characters or HTML entities
  • Review web server access logs for POST requests to wp-signup.php or wp-login.php?action=register with suspicious payloads in the email field

Monitoring Recommendations

  • Enable WordPress audit logging to capture new user registrations and admin page access patterns
  • Monitor administrator session activity for anomalous API calls originating from the wp-admin interface
  • Alert on modifications to privileged WordPress user accounts following access to plugin log pages

How to Mitigate CVE-2026-75962

Immediate Actions Required

  • Update the Post SMTP plugin to version 4.0.2 or later on all WordPress installations
  • Disable public user registration on Multisite installations until the patch is applied
  • Clear existing Post SMTP email log entries after reviewing them for malicious payloads
  • Rotate administrator credentials and review account activity if evidence of exploitation is found

Patch Information

The vendor addressed the issue in Post SMTP version 4.0.2. The fix is documented in the plugin changeset for version 4.0.2 and the email log service update. Site administrators should apply the update through the WordPress plugin updater or by replacing the plugin files manually.

Workarounds

  • Disable the Post SMTP plugin until the patched version can be installed
  • Set users_can_register to false and disable Multisite public registration via Network Settings
  • Restrict access to the Post SMTP email log page through a web application firewall rule or role-based access control
  • Deploy a WAF rule to block registration requests whose user_email parameter contains <, >, or &# sequences
bash
# Configuration example: disable registration while patching
wp option update users_can_register 0
wp network meta update 1 registration none
wp plugin update post-smtp --version=4.0.2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.