CVE-2024-52436

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a through <= 2.9.9.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpexperts:post_smtp:*:*:*:*:*:wordpress:*:*

History

23 Apr 2026, 15:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 7.6

01 Apr 2026, 16:20

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects Post SMTP: from n/a through <= 2.9.9.
References
  • {'url': 'https://patchstack.com/database/vulnerability/post-smtp/wordpress-post-smtp-plugin-2-9-9-sql-injection-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/post-smtp/vulnerability/wordpress-post-smtp-plugin-2-9-9-sql-injection-vulnerability?_s_id=cve -

20 Nov 2024, 15:24

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/post-smtp/wordpress-post-smtp-plugin-2-9-9-sql-injection-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/post-smtp/wordpress-post-smtp-plugin-2-9-9-sql-injection-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:wpexperts:post_smtp:*:*:*:*:*:wordpress:*:*
First Time Wpexperts post Smtp
Wpexperts
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 7.2

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Post SMTP permite la inyección SQL ciega. Este problema afecta a Post SMTP: desde n/a hasta 2.9.9.

18 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 15:15

Updated : 2026-04-23 15:21


NVD link : CVE-2024-52436

Mitre link : CVE-2024-52436

CVE.ORG link : CVE-2024-52436


JSON object : View

Products Affected

wpexperts

  • post_smtp
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')