CVE-2026-81278
published 2026-08-31CVE-2026-81278: Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post…
PriorityP430medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.29%
19.4th percentile
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Post SMTP: from 4.0.0 through beta.1.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wpexperts | post_smtp | 4.0.0 – beta.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WPExperts Post SMTP Plugin up to beta.1 on WordPress authorization
vuldb·2026-08-31·CVSS 5.4
CVE-2026-81278 [MEDIUM] WPExperts Post SMTP Plugin up to beta.1 on WordPress authorization
A vulnerability was found in WPExperts Post SMTP Plugin up to beta.1 on WordPress. It has been classified as problematic. This affects an unknown part. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2026-81278. Remote exploitation of the attack is possible. No exploit is available.
GHSA
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.
ghsa_unreviewed·2026-08-31
CVE-2026-81278 [MEDIUM] CWE-862 Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Post SMTP: from 4.0.0 through beta.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-31
Published