Configure SMTP
Configure SMTP has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Configure SMTP has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dimas Maulana. Configure SMTP is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2024-27192Configure SMTP <= 3.1 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Configure SMTP
Author
Scott Reilly
Configure SMTP mailing in WordPress, including support for sending email via SSL/TLS (such as Gmail). This plugin is the official successor to the original SMTP plugin for WordPress (wpPHPMailer). Use this plugin to customize the SMTP mailing system used by default by WordPress to handle outgoing emails. It offers you the ability to specify: SMTP host name SMTP port number If SMTPAuth (authentication) should be used SMTP username SMTP password If the SMTP connection needs to occur over ssl or tls In addition, you can instead indicate that you wish to use Gmail to handle outgoing email, in which case the above settings are automatically configured to values appropriate for Gmail, though you’ll need to specify your Gmail email address (including the “@gmail.com”) and password. Regardless of whether SMTP is enabled, the plugin provides you the ability to define the name and email of the ‘From:’ field for all outgoing emails. A simple test button is also available that allows you to send a test email to yourself to check if sending email has been properly configured for your site. Links: Plugin Homepage | Plugin Directory Page | GitHub | Author Homepage
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C