CVE-2026-7621
Deferred Deferred - Pending Action
SMTP2GO Log Data Exposure in WordPress Plugin

Publication date: 2026-05-28

Last updated on: 2026-05-28

Assigner: Wordfence

Description
The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.16.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to truncate all SMTP2GO log records from the database or download a CSV export of all SMTP log data including recipient addresses, sender addresses, message subjects, and API response data.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-28
Last Modified
2026-05-28
Generated
2026-06-17
AI Q&A
2026-05-28
EPSS Evaluated
2026-06-16
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
smtp2go smtp2go_for_wordpress to 1.16.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The SMTP2GO for WordPress – Email Made Easy plugin is vulnerable because it does not properly verify whether a user is authorized to perform certain actions.

This flaw allows authenticated users with subscriber-level access or higher to either delete all SMTP2GO log records from the database or download a CSV export containing sensitive SMTP log data.

  • The exported data includes recipient addresses, sender addresses, message subjects, and API response data.
Impact Analysis

This vulnerability can impact you by allowing unauthorized users with low-level access to manipulate or access sensitive email log data.

  • They can truncate (delete) all SMTP2GO log records, potentially causing loss of important email tracking information.
  • They can also download a CSV file containing detailed SMTP log data, exposing recipient and sender email addresses, message subjects, and API response details.
Mitigation Strategies

The vulnerability affects all versions of the SMTP2GO for WordPress plugin up to and including 1.16.0. Immediate mitigation steps include updating the plugin to a version later than 1.16.0 where the issue is fixed.

Additionally, restrict subscriber-level user permissions and monitor access to SMTP2GO log records to prevent unauthorized truncation or export of sensitive email log data.

Compliance Impact

The vulnerability allows authenticated attackers with subscriber-level access to download a CSV export of all SMTP log data, which includes recipient addresses, sender addresses, message subjects, and API response data.

This unauthorized access to potentially sensitive email log data could lead to violations of data protection regulations such as GDPR and HIPAA, which require strict controls on access to personal and sensitive information.

By enabling unauthorized data access and export, the vulnerability undermines compliance with these standards that mandate confidentiality and proper authorization for handling personal data.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7621. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart