LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-2559

Published
CVSS5.3
Severitymedium
WeaknessCWE-862
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the site's Office 365 OAuth mail configuration (access token, refresh token, and user email) via a crafted URL. The configuration option is used during wizard setup of Microsoft365 SMTP, only available in the Pro option of the plugin. This could cause an Admi

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2559

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2559.