Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
WordPress Plugin 'WP Mail SMTP' Allows Unauthenticated File Upload
MINI-3gfh-6w4w-4qr3
Summary
An unauthenticated attacker can upload arbitrary files to a WordPress site using the 'WP Mail SMTP' plugin, which may lead to malicious code execution. This affects WordPress sites using the plugin to manage email settings. Users should update the plugin to the latest version to prevent unauthorized file uploads.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| – | gitlab-cng-fips-18.0 | All versions | – |
| – | gitlab-base-fips-18.0 | All versions | – |
| – | gitlab-container-registry-fips-18.0 | All versions | – |
| – | gitlab-logger-fips-18.0 | All versions | – |
| – | gitlab-shell-fips-18.0 | All versions | – |
Original title
MINI-3gfh-6w4w-4qr3
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026