Known vulnerabilities in Postie
Postie allows you to create posts via email, including many advanced features not found in WordPress's default Post by Email feature.
5Reported vulnerabilities
6.4Highest CVSS score
1.9.80Latest version
10,000+Active installs
What to do now
Update Postie to 1.9.74 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2019-20204 | Medium | 3.4% | 1.9.40 and earlier | 1.9.41 |
January 2, 2020 |
| CVE-2019-20203 | Medium | 2.1% | 1.9.40 and earlier | 1.9.41 |
January 2, 2020 |
| CVE-2012-2580 | Medium | 3.7% | 1.5.14 and earlier 1.4.3 to 1.4.3 (inclusive) |
1.4.10 |
June 20, 2014 |
| CVE-2025-63020 | Medium | 0.2% | 1.9.73 and earlier | 1.9.74 |
December 31, 2025 |
| CVE-2024-5200 | Medium | 0.2% | 1.9.70 and earlier | 1.9.71 |
September 8, 2025 |