Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Post SMTP
Saad Iqbal
Developer
3.6.1
Latest version
400,000
Installations
Oct 29, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
20 fixed
10 Mitigation rules
Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure vulnerability
<= 3.6.0
Nov 3, 2025
Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update vulnerability
<= 3.4.1
Sep 2, 2025
Account Takeover Vulnerability
<= 3.2.0
Jul 21, 2025
Authenticated (Administrator+) SQL Injection via columns Parameter vulnerability
<= 3.1.2
Mar 8, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 3.0.2
Feb 17, 2025
Broken Access Control vulnerability
<= 2.9.11
Jan 7, 2025
SQL Injection vulnerability
<= 2.9.9
Nov 15, 2024
Authenticated SQL Injection vulnerability
<= 2.9.3
May 30, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 2.8.6
Mar 16, 2024
Authorization Bypass via type connect-app API vulnerability
<= 2.8.7
Jan 10, 2024
Broken Access Control on API vulnerability
<= 2.8.6
Jan 5, 2024
Unauthenticated Stored Cross-Site Scripting via device vulnerability
<= 2.8.7
Jan 3, 2024
Reflected Cross-Site Scripting via msg vulnerability
<= 2.8.6
Jan 3, 2024
Authenticated (Administrator+) SQL Injection vulnerability
< 2.6.1
Oct 4, 2023
Reflected Cross Site Scripting (XSS) vulnerability
< 2.5.8
Jul 18, 2023
Unauthenticated Stored Cross-Site Scripting via Email vulnerability
<= 2.5.7
Jul 12, 2023
Account Takeover via CSRF vulnerability
< 2.5.7
Jul 4, 2023
Arbitrary Log Deletion via CSRF vulnerability
< 2.5.7
Jul 4, 2023
Authenticated Blind Server-Side Request Forgery (SSRF) vulnerability
<= 2.1.6
Sep 5, 2022
Cross-Site Request Forgery (CSRF) nonce validation vulnerability
<= 2.0.20
Feb 11, 2021