Detects WordPress installs running the Post SMTP plugin at version 3.8.0 or earlier. The plugin's email log display renders the event_type field from the Reporting and Tracking extension without output escaping. An unauthenticated attacker can inject JavaScript payloads via email tracking callbacks that execute when an admin views the email logs, enabling session hijacking and admin account takeover.
Is your app exploitable through CVE-2026-3090?
Scan your domain free