CVE-2017-18603: Postman-Smtp Project Postman-Smtp
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.
Affected products
- Postman-Smtp Project Postman-Smtp: up to and including 2017-10-04
Published 2019-09-10. Last modified 2026-06-17.