Description

A critical security vulnerability identified as CVE-2023-6875 has been discovered in the widely used POST as in the POST SMTP Mailer plugin versions up to 2.8.7 and is caused by an authorization bypass issue within the plugin’s connect-app REST endpoint. Due to improper validation and a type-juggling weakness, attackers can interact with sensitive functionality without proper authentication controls. Successful exploitation enables threat actors to reset API keys, access email logs, and retrieve password reset messages sent by WordPress. Since password reset emails often contain account recovery links, attackers can leverage this information to gain unauthorized access to administrative accounts and ultimately take control of the affected website. In addition to the authorization bypass flaw, researchers also identified a Stored Cross-Site Scripting (XSS) vulnerability resulting from insufficient sanitization of the “device” header. An unauthenticated attacker could inject malicious scripts that execute within administrative sessions, increasing the potential impact of compromise. The issue was reported through Wordfence’s Holiday Bug Extravaganza program, and the plugin developer responded by releasing a security patch in version 2.8.8.