{"id":1213,"date":"2025-11-19T18:12:19","date_gmt":"2025-11-19T18:12:19","guid":{"rendered":"https:\/\/1stattorneys.ng\/?p=1213"},"modified":"2026-01-09T06:01:02","modified_gmt":"2026-01-09T06:01:02","slug":"wordpress-security-attackers-actively-exploiting-critical","status":"publish","type":"post","link":"https:\/\/1stattorneys.ng\/?p=1213","title":{"rendered":"[WordPress Security] Attackers Actively Exploiting Critical"},"content":{"rendered":"<p>[WordPress Security] Attackers Actively Exploiting Critical Vuln=<br \/>erability in Post SMTP Plugin<\/p>\n<p>=20<br \/>=20<br \/>=20<\/p>\n<p>=20<br \/>=20<br \/>=20<br \/>=20<br \/>=20<br \/>@media only screen and (max-w=<br \/>idth:639px){img.stretch-on-mobile,.hs_rss_email_entries_table img,.hs-stret=<br \/>ch-cta .hs-cta-img{height:auto !important;width:100% !important}<br \/>.display_block_on_small_screens{display:block}.hs_padded{padding-left:20px =<br \/>!important;padding-right:20px !important}<br \/>.hs-hm,table.hs-hm{display:none}.hs-hd{display:block !important}table.hs-hd=<br \/>{display:table !important}<br \/>}@media only screen and (max-width:639px){.hse-border-m{border-left:0px sol=<br \/>id #008cc1 !important;border-right:0px solid #008cc1 !important;box-sizing:=<br \/>border-box}<br \/>.hse-border-bottom-m{border-bottom:0px solid #008cc1 !important}.hse-border=<br \/>-top-m{border-top:0px solid #008cc1 !important}<br \/>.hse-border-top-hm{border-top:none !important}.hse-border-bottom-hm{border-=<br \/>bottom:none !important}<br \/>}.moz-text-html .hse-column-container{max-width:600px !important;width:600p=<br \/>x !important}<br \/>.moz-text-html .hse-column{display:table-cell;vertical-align:top}.moz-text-=<br \/>html .hse-section .hse-size-4{max-width:200px !important;width:200px !impor=<br \/>tant}<br \/>.moz-text-html .hse-section .hse-size-8{max-width:400px !important;width:40=<br \/>0px !important}<br \/>.moz-text-html .hse-section .hse-size-12{max-width:600px !important;width:6=<br \/>00px !important}<br \/>@media only screen and (min-width:640px){.hse-column-container{max-width:60=<br \/>0px !important;width:600px !important}<br \/>.hse-column{display:table-cell;vertical-align:top}.hse-section .hse-size-4{=<br \/>max-width:200px !important;width:200px !important}<br \/>.hse-section .hse-size-8{max-width:400px !important;width:400px !important}=<br \/>.hse-section .hse-size-12{max-width:600px !important;width:600px !important=<br \/>}<br \/>}@media only screen and (max-width:639px){.hse-body-wrapper-td{padding-top:=<br \/>20px !important}<br \/>#section-0 .hse-column-container{background-color:#fff !important} }@media =<br \/>only screen and (max-width:639px){ #section-1 .hse-column-container{backgro=<br \/>und-color:#fff !important}<br \/>}@media only screen and (max-width:639px){ #section-2 .hse-column-container=<br \/>{background-color:#fff !important}<br \/>}@media screen and (max-width:639px){.social-network-cell{display:inline-bl=<br \/>ock} }<br \/>@media only screen and (max-width:639px){ #section_176167242849417 .hse-col=<br \/>umn-container{padding-top:0px !important;padding-bottom:0px !important}<br \/>#section_176167242849417 .hse-column-container{background-color:#fff !impor=<br \/>tant}<br \/>}@media only screen and (max-width:639px){ #section-3 .hse-column-container=<br \/>{background-color:#fff !important}<br \/>}@media only screen and (max-width:639px){ #section-4 .hse-column-container=<br \/>{background-color:#fff !important}<br \/>}@media only screen and (max-width:639px){ #section-5 .hse-column-container=<br \/>{background-color:#fff !important}<br \/>}@media only screen and (max-width:639px){ #section-6 .hse-column-container=<br \/>{background-color:#fff !important}<br \/>}@media only screen and (max-width:639px){ #section-7 .hse-column-container=<br \/>{background-color:#fff !important}<br \/>}@media only screen and (max-width:639px){.hse-body-wrapper-td{padding-bott=<br \/>om:20px !important}<br \/>#section-8 .hse-column-container{background-color:#fff !important} }#hs_body #hs_cos_wrapper_main a[x=<br \/>-apple-data-detectors]{color:inherit !important;text-decoration:none !impor=<br \/>tant;font-size:inherit !important;font-family:inherit !important;font-weigh=<br \/>t:inherit !important;line-height:inherit !important}<br \/>a{text-decoration:underline}p{margin:0}body{-ms-text-size-adjust:100%;-webk=<br \/>it-text-size-adjust:100%;-webkit-font-smoothing:antialiased;moz-osx-font-sm=<br \/>oothing:grayscale}<br \/>table{border-spacing:0;mso-table-lspace:0;mso-table-rspace:0}table,td{borde=<br \/>r-collapse:collapse}<br \/>img{-ms-interpolation-mode:bicubic}p,a,li,td,blockquote{mso-line-height-rul=<br \/>e:exactly}<br \/>.ShadowHTML p,.sh-modified-inline p{margin:0}<\/p>\n<div>We urge users to update their sites with the latest patched v=<br \/>ersion of this plugin as soon as possible.<\/div>\n<p>=20<\/p>\n<div>\n<div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<div>\n<p>On October 11th, 2025, =<br \/>we received a submission for an Account Takeover via Email Log Disclosure vulnerability in\u00a0Post =<br \/>SMTP, a WordPress plugin with more than 400,000 active installations.<\/p>\n<p>\u00a0<\/p>\n<p>This vulnerability makes it possible for an u=<br \/>nauthenticated attacker to view email logs, including password reset emails=<br \/>, and change the password of any user, including an administrator, which al=<br \/>lows them to take over the account and the website.<\/p>\n<p>\u00a0<\/p>\n<p>Read The Full Post Here<\/p>\n<p>\u00a0<\/p>\n<p>We originally published this vulnerability on=<br \/>October 31st, 2025 and our records indicate that attackers started exploit=<br \/>ing the issue the next day on November 1st, 2025. It appears mass exploitation started the following day, on Novemb=<br \/>er 2nd, 2025. The Wordfence Firewall has already blocked over 10,300 exploi=<br \/>t attempts targeting this vulnerability.<\/p>\n<p>\u00a0<\/p>\n<p>Wordfence Premium,\u00a0Wo=<br \/>rdfence Care, and\u00a0Wordfence Response\u00a0users receive=<br \/>d a firewall rule to protect against any exploits targeting this vulnerabil=<br \/>ity on October 15, 2025. Sites using the free version of Wordfence received=<br \/>the same protection 30 days later on November 14, 2025.<\/p>\n<p>\u00a0<\/p>\n<p>Considering this vulnerabil=<br \/>ity is under active attack, we urge users to ensure their sites are updated=<br \/>with the latest patched version of Post SMTP, version 3.6.1 at the time of=<br \/>this writing,\u00a0as soon as possible.<\/p>\n<\/div>\n<\/div>\n<div>\n<p><strong>READ THE FULL POST HERE<\/strong><\/p>\n<\/div>\n<div>\u00a0<\/div>\n<div>\n<div>\n<p>=F0=9F=8F=86 Current Bug Bounty=<br \/>Promotions: =F0=9F=8F=86\u00a0<\/p>\n<p>\u00a0<\/p>\n<p><strong>=F0=9F=93=81 The LFInder Challenge: Refine your LFI hunting skills with an expanded scope.\u00a0<br \/>=F0=9F=94=8D Now through November 24, 2025, all LFI vulnerabilities in sof=<br \/>tware with at least 25 active installs are considered in-scope for all rese=<br \/>archers, regardless of researcher tier, AND earn a\u00a0<strong>30% bonus o=<br \/>n all Local File Inclusion vulnerability submissions<\/strong>\u00a0not alre=<br \/>ady increased by another promotion.<\/strong><\/p>\n<p>Read our guide on how to find =<br \/>LFI vulnerabilities to level up your skills for this promotion.<\/p>\n<p>Join The Wordfence Bug Bounty Program today: Submit bold, Earn big! =F0=9F=94=A5<\/p>\n<\/div>\n<div class=\"3D=\">\u00a0<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<div>Follow Wordfence On Social Media =<br \/>For The Latest WordPress Security Updates, Alerts, and Education\u00a0=<\/div>\n<\/div>\n<div>\n<p><img \/><\/p>\n<p><img \/><\/p>\n<p><img \/><\/p>\n<p><img \/><\/p>\n<p><img \/><\/p>\n<p><img \/><\/p>\n<p><img \/><\/p>\n<\/div>\n<div>\n<div>\n<p>Did you know that we publish educational and informational WordP=<br \/>ress security\u00a0content almost daily on most of your favorite soc=<br \/>ial media platforms?<\/p>\n<p>Follow us =<br \/>on your platforms of choice and join us\u00a0in r\/wordfence &#8211; a new home for all things WordPress security related.<\/p>\n<\/div>\n<\/div>\n<div>\u00a0<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<div>The Full Product Lineup<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\u00a0<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<div>\n<p>Defiant, Inc., 1700 Westlake Ave N STE 200\u00a0<\/p>\n<p>Seattle, WA \u00a098109\u00a0United States<\/p>\n<p>Unsubscribe Manage Preferences<\/p>\n<\/div>\n<\/div>\n<div>\n<div>\n<p><img \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<div>=20<br \/>=20\n<div>=20\n<div>\n<div>\n<div>\n<p>You&#8217;re receiving this email because you signed up to the Wordfe=<br \/>nce WordPress security mailing list.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>=20<br \/><img \/><\/p>\n<\/div>\n<\/div>\n\n<p>[flipbook]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[WordPress Security] Attackers Actively Exploiting Critical Vuln=erability in Post SMTP Plugin =20=20=20 =20=20=20=20=20@media only screen and (max-w=idth:639px){img.stretch-on-mobile,.hs_rss_email_entries_table img,.hs-stret=ch-cta .hs-cta-img{height:auto !important;width:100% !important}.display_block_on_small_screens{display:block}.hs_padded{padding-left:20px =!important;padding-right:20px !important}.hs-hm,table.hs-hm{display:none}.hs-hd{display:block !important}table.hs-hd={display:table !important}}@media only screen and (max-width:639px){.hse-border-m{border-left:0px sol=id #008cc1 !important;border-right:0px solid #008cc1 !important;box-sizing:=border-box}.hse-border-bottom-m{border-bottom:0px solid #008cc1 !important}.hse-border=-top-m{border-top:0px solid #008cc1 !important}.hse-border-top-hm{border-top:none !important}.hse-border-bottom-hm{border-=bottom:none !important}}.moz-text-html .hse-column-container{max-width:600px !important;width:600p=x !important}.moz-text-html .hse-column{display:table-cell;vertical-align:top}.moz-text-=html .hse-section .hse-size-4{max-width:200px !important;width:200px !impor=tant}.moz-text-html .hse-section .hse-size-8{max-width:400px !important;width:40=0px !important}.moz-text-html [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1213","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=\/wp\/v2\/posts\/1213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1213"}],"version-history":[{"count":4,"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=\/wp\/v2\/posts\/1213\/revisions"}],"predecessor-version":[{"id":1242,"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=\/wp\/v2\/posts\/1213\/revisions\/1242"}],"wp:attachment":[{"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/1stattorneys.ng\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}