CVE · High

CVE-2025-13516 — SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers [suremails] < 1.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13516 SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers [suremails] < 1.9.1 Unrestricted Upload of File with Dangerous Type High 8.1 < 1.9.1 1.9.1 2025-12-01

CVE-2025-13516

The SureMail plugin for WordPress contains a flaw in its attachment handling mechanism, allowing unauthenticated users to upload malicious files with potentially hazardous types into a publicly accessible directory. This occurs due to insufficient validation of file extensions and content types within the save_file() function in inc/emails/handler/uploads.php.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.