Ongoing Post SMTP plugin exploitation threatens widespread WordPress site compromise

BleepingComputer reports that at least 210,000 WordPress sites could be hijacked in intrusions exploiting a critical security flaw in the Post SMTP plugin, tracked as CVE-2025-11833, which have been underway since the beginning of November.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Article Link: https://www.scworld.com/brief/ongoing-post-smtp-plugin-exploitation-threatens-widespread-wordpress-site-compromise