cleantalk
Vulnerabilities and Security Researches

YaySMTP – Simple WP SMTP Mail, CVE-2025-53256

CVE, Research URL

CVE-2025-53256

Published on
Jun 27, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows SQL Injection.This issue affects YaySMTP: from n/a through 2.6.5.
Affected versions
Min -, max 6.8.1.
Status
vulnerable