CVE-2026-2559
Last modified
CVE-2026-2559 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonce verification. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and including, 3.8.0. This is due to the function being hooked to `admin_init` without any `current_user_can()` check or nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the site's Office 365 OAuth mail configuration (access token, refresh token, and user email) via a crafted URL. The configuration option is used during wizard setup of Microsoft365 SMTP, only available in the Pro option of the plugin. This could cause an Administrator to believe an attacker-controlled Azure app is their own, and lead them to connect the plugin to the attacker's account during configuration after upgrading to Pro.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-2559?
How severe is CVE-2026-2559?
How do I fix CVE-2026-2559?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25584iccDEV provides a set of libraries and tools that allow for …7.8
- CVE-2026-25585iccDEV provides a set of libraries and tools that allow for …7.8
- CVE-2026-25586SandboxJS is a JavaScript sandboxing library. Prior to 0.8.2…10
- CVE-2026-25587SandboxJS is a JavaScript sandboxing library. Prior to 0.8.2…10
- CVE-2026-25588RedisTimeSeries is a time-series module for Redis. In all ve…8.8
- CVE-2026-25589RedisBloom is a probabilistic data structures module for Red…8.8
- CVE-2026-25590The GLPI Inventory Plugin handles network discovery, invento…6.1
- CVE-2026-25591New API is a large language mode (LLM) gateway and artificia…6.5
- CVE-2026-25592Semantic Kernel is an SDK used to build, orchestrate, and de…9.9
- CVE-2026-25593OpenClaw is a personal AI assistant. Prior to 2026.1.20, an …8.4
- CVE-2026-25594InvoicePlane is a self-hosted open source application for ma…4.8
- CVE-2026-25595InvoicePlane is a self-hosted open source application for ma…4.8
Are you affected by CVE-2026-2559?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
