
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62123 is a Cross-Site Request Forgery (CSRF) vulnerability in the WP Gmail SMTP plugin (by inkthemes/Ink themes) for WordPress. It affects all versions of the plugin through 1.0.7 and allows network-based attackers to perform unauthorized actions by tricking an authenticated user into visiting a malicious page. The vulnerability was reported by Patchstack and published on December 31, 2025, with subsequent CVE record updates through April 2026. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to properly validate that state-changing requests originate from legitimate, authenticated sessions. An attacker can craft a malicious web page containing a forged HTTP request targeting the plugin's administrative endpoints; when an authenticated WordPress administrator visits the page, the browser automatically includes session credentials, causing the server to execute the forged request. No privileges are required on the attacker's side, but user interaction (victim visiting the malicious page) is necessary. No public proof-of-concept exploit code has been identified at this time (Patchstack, Red Hat CVE).
Successful exploitation allows an attacker to modify the WP Gmail SMTP plugin's settings or configuration without authorization, such as changing SMTP credentials or email routing settings. This could result in email interception, redirection of outbound WordPress emails to attacker-controlled servers, or disruption of email-based functionality (e.g., password resets, notifications). The confidentiality and availability impacts are rated as none, with only a low integrity impact per the CVSS assessment, limiting the scope to configuration tampering rather than full system compromise (Patchstack).
There is no evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog. No public exploit code or weaponized toolkits have been identified. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported (Red Hat CVE).
/wp-content/plugins/wp-gmail-smtp/ paths or plugin metadata in page source)./wp-admin/options.php or the plugin's own settings handler), with attacker-controlled parameter values (e.g., modified SMTP credentials or server address)./wp-admin/options.php or plugin-specific admin pages) from unusual referrer URLs or external origins.Users should update the WP Gmail SMTP plugin to a version beyond 1.0.7 if a patched release is available from the plugin developer (inkthemes). If no patched version is available, administrators should consider deactivating and removing the plugin until a fix is released. As a general WordPress hardening measure, administrators should avoid clicking unsolicited links while logged into the WordPress admin panel, and consider using a Web Application Firewall (WAF) with CSRF protection rules. Monitoring plugin settings for unauthorized changes is also recommended (Patchstack, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."