Zero-day in WordPress SMTP plugin abused to reset admin account passwords

A patch has been released earlier this week but many WordPress sites remained unpatched —as usual.

Article Link: https://www.zdnet.com/article/zero-day-in-wordpress-smtp-plugin-abused-to-reset-admin-account-passwords/#ftag=RSSbaffb68