cleantalk
Vulnerabilities and Security Researches

FluentSMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin, PSC-2026-64658

PSC, Research URL

PSC-2026-64658

Published on
May 26, 2026
Research Description
SMTP and email routing plugins hold highly sensitive operational data because they connect WordPress to external mail infrastructure, API credentials, OAuth-based providers, email logs, and resend workflows. Weak controls in this layer can expose tokens, disclose private email content, alter transactional mail routing, or allow unauthorized users to resend messages. FluentSMTP version 2.2.95 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64658, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for mail delivery and email logging plugins.
Affected versions
Min 2.2.95, max 2.2.95.
Status
SAFE & CERTIFIED