The POST SMTP Mailer WordPress plugin prior to 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow malicious users to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wpexperts post smtp |