CVE-2017-18603: Postman-Smtp Project Postman-Smtp

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.

Affected products

Published 2019-09-10. Last modified 2026-06-17.