CVE-2025-62123
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62123 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Gmail SMTP plugin (by inkthemes/Ink themes) for WordPress. It affects all versions of the plugin through 1.0.7 and allows network-based attackers to perform unauthorized actions by tricking an authenticated user into visiting a malicious page. The vulnerability was reported by Patchstack and published on December 31, 2025, with subsequent CVE record updates through April 2026. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate that state-changing requests originate from legitimate, authenticated sessions. An attacker can craft a malicious web page containing a forged HTTP request targeting the plugin's administrative endpoints; when an authenticated WordPress administrator visits the page, the browser automatically includes session credentials, causing the server to execute the forged request. No privileges are required on the attacker's side, but user interaction (victim visiting the malicious page) is necessary. No public proof-of-concept exploit code has been identified at this time (Patchstack, Red Hat CVE).

Impact

Successful exploitation allows an attacker to modify the WP Gmail SMTP plugin's settings or configuration without authorization, such as changing SMTP credentials or email routing settings. This could result in email interception, redirection of outbound WordPress emails to attacker-controlled servers, or disruption of email-based functionality (e.g., password resets, notifications). The confidentiality and availability impacts are rated as none, with only a low integrity impact per the CVSS assessment, limiting the scope to configuration tampering rather than full system compromise (Patchstack).

Exploitability

There is no evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog. No public exploit code or weaponized toolkits have been identified. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the WP Gmail SMTP plugin (version ≤ 1.0.7) via passive enumeration (e.g., checking /wp-content/plugins/wp-gmail-smtp/ paths or plugin metadata in page source).
  2. Craft malicious page: Create an HTML page containing a hidden form or JavaScript that automatically submits a POST request to the target WordPress site's admin endpoint responsible for saving WP Gmail SMTP settings (e.g., /wp-admin/options.php or the plugin's own settings handler), with attacker-controlled parameter values (e.g., modified SMTP credentials or server address).
  3. Deliver to victim: Trick an authenticated WordPress administrator into visiting the malicious page via phishing, a malicious link, or a compromised third-party site.
  4. Trigger forged request: The victim's browser automatically includes their WordPress session cookies with the forged request, causing the server to process it as a legitimate admin action and update the plugin's SMTP configuration.
  5. Achieve objective: With SMTP settings modified, the attacker can redirect outbound WordPress emails (including password reset links) to an attacker-controlled mail server, enabling credential harvesting or further account compromise (Patchstack).

Indicators of compromise

  • Logs: WordPress admin audit logs or server access logs showing unexpected POST requests to plugin settings endpoints (e.g., /wp-admin/options.php or plugin-specific admin pages) from unusual referrer URLs or external origins.
  • Configuration: Unexpected changes to WP Gmail SMTP plugin settings, particularly SMTP host, port, username, or password fields modified without administrator action.
  • Email: Outbound WordPress emails (password resets, notifications) failing to deliver or being routed to unexpected mail servers.

Mitigation and workarounds

Users should update the WP Gmail SMTP plugin to a version beyond 1.0.7 if a patched release is available from the plugin developer (inkthemes). If no patched version is available, administrators should consider deactivating and removing the plugin until a fix is released. As a general WordPress hardening measure, administrators should avoid clicking unsolicited links while logged into the WordPress admin panel, and consider using a Web Application Firewall (WAF) with CSRF protection rules. Monitoring plugin settings for unauthorized changes is also recommended (Patchstack, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management