Cyber Posture

CVE-2025-22800

Medium

Published: 13 January 2025

Published
13 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score 0.0007 20.3th percentile
Risk Priority 9 60% EPSS · 20% KEV · 20% CVSS

Description

Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through <= 2.9.11.

Security Summary

CVE-2025-22800 is a missing authorization vulnerability (CWE-862) in the Post SMTP WordPress plugin developed by Saad Iqbal. The flaw, which allows exploiting incorrectly configured access control security levels, affects all versions of the post-smtp plugin up to and including 2.9.11. Published on 2025-01-13, it carries a CVSS v3.1 base score of 4.3 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).

A low-privileged user (PR:L) can exploit this vulnerability remotely over the network (AV:N) with low complexity (AC:L) and without requiring user interaction (UI:N). Successful exploitation results in low-impact denial of service (A:L), with no effects on confidentiality or integrity and no change in scope (S:U).

The Patchstack advisory provides details on this broken access control issue in Post SMTP version 2.9.11 and related mitigation guidance, accessible at https://patchstack.com/database/Wordpress/Plugin/post-smtp/vulnerability/wordpress-post-smtp-plugin-2-9-11-broken-access-control-vulnerability?_s_id=cve.

Details

CWE(s)
CWE-862

Affected Products

wpexperts
post smtp
≤ 2.9.12

References