CVE-2022-2352
CVE-2022-2352 is a high-severity vulnerability in Wpexperts Post Smtp with a CVSS 3.x base score of 7.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-918.
Key facts
- Severity: High (CVSS 3.x base score 7.2)
- EPSS exploit prediction: 1% (64th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-918
- Affected product: Wpexperts Post Smtp
- Published:
- Last modified:
Description
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
Frequently asked questions
- What is CVE-2022-2352?
- The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
- How severe is CVE-2022-2352?
- CVE-2022-2352 has a CVSS 3.x base score of 7.2, rated high severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2022-2352 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (64th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-2352?
- CVE-2022-2352 affects Wpexperts Post Smtp. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2022-2352?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2022-2352 published?
- CVE-2022-2352 was published on 2022-09-26 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:wpexperts:post_smtp:*:*:*:*:*:wordpress:*:*
More vulnerabilities in Wpexperts Post Smtp
- CVE-2023-6875 — Critical (CVSS 9.8): The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for…
- CVE-2023-3179 — High (CVSS 8.8): The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could…
- CVE-2023-52233 — High (CVSS 8.6): Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email…
- CVE-2024-52436 — High (CVSS 7.6): Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post…
- CVE-2025-0521 — High (CVSS 7.2): The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in…
- CVE-2024-5207 — High (CVSS 7.2): The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin…
All CVEs affecting Wpexperts Post Smtp →
Other CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities
- CVE-2026-54734 — Critical (CVSS 10.0): Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate…
- CVE-2026-76193 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-69502 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-65801 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges…
- CVE-2026-48331 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-54735 — Critical (CVSS 10.0): Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version…
Browse all CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities →