A vulnerability classified as problematic has been found in saadiqbal Post SMTP Plugin up to 3.8.0 on WordPress. This issue affects some unknown processing. This manipulation of the argument event_type causes cross site scripting.

This vulnerability appears as CVE-2026-3090. The attack may be initiated remotely. There is no available exploit.