All verified exploits

CVE-2026-3090 Stored XSS via Post SMTP Email Logs

Deterministic high WordPress Added cve-verified-cve-2026-3090

Detects WordPress installs running the Post SMTP plugin at version 3.8.0 or earlier. The plugin's email log display renders the event_type field from the Reporting and Tracking extension without output escaping. An unauthenticated attacker can inject JavaScript payloads via email tracking callbacks that execute when an admin views the email logs, enabling session hijacking and admin account takeover.

Related WordPress exploits

Is your app exploitable through CVE-2026-3090?

Scan your domain free