Postie
Postie has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2025; all 5 are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 5 of the records (100%).
Every one of the 5 issues recorded for Postie has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (2) reported by V1n1v131r4. Postie is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2012-2580Postie < 1.4.10 - Cross-Site Scripting
Read the full analysisVulnerability Records

Postie
Author
Wayne Allen
Postie offers many advanced features for creating posts by email, including the ability to assign categories by name, included pictures and videos, and automatically strip off signatures. Postie supports both IMAP and POP including SSL/TLS. There is also an extensive set of filters/actions for developers to extend Postie’s functionality. For usage notes, see the other notes page. More info at http://PostiePlugin.com/ Features Supports IMAP or POP3 servers SSL and TLS supported Control who gets to post via email Set defaults for category, status, post format, post type and tags. Set title, category, status, post format, post type, date, comment control and tags in email to override defaults. Specify post excerpt (including excerpt only images). Use plain text or HTML version of email. Remove headers and footers from email (useful for posting from a mailing list). Optionally send emails on post success/failure. Control the types of attachments that are allowed by file name (wildcards allowed) and MIME type. Optionally make the first image the featured image. Gallery support. Control image placement with plain text email. Templates for images so they look the way you want. Templates for videos. Templates for audio files. Templates for other attachments. Email replies become comments. Developers Several filter hooks available for custom processing of emails. More developer info at http://postieplugin.com/extending/ Usage Please visit our site at http://postieplugin.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C