plugin

Easy Wp Smtp Vulnerabilities

8 known security issues reported for the Easy Wp Smtp WordPress plugin. Most recent disclosed Jun 12, 2024.

1 critical 3 high 2 medium 2 low

Running Easy Wp Smtp on your site? Check whether your installed version is affected.

Scan your site free

Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UI

low

The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated att...

CVSS:
2.7
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Jun 12, 2024

CVE-2024-3073 on NVD →

Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Remote Code Execution

high

The Easy WP SMTP plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.5.1 possibly via the 'admin_init' function (as part of the SMTP import/export functionality). This allows administrator-level attackers to execute code on the server.

CVSS:
7.2
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Nov 30, 2022

CVE-2022-42699 on NVD →

Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Arbitrary File Deletion

medium

The Easy WP SMTP plugin for WordPress is vulnerable to Arbitrary File Deletion versions up to, and including, 1.5.1. This is possibly due to the SMTP import/export functionality. This makes it possible for administrator-level attackers to arbitrarily delete files on the server, including critical files for the website'...

CVSS:
6.5
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Nov 30, 2022

CVE-2022-45829 on NVD →

Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Directory Traversal

low

The Easy WP SMTP plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.5.1 possibly via the 'admin_init' function (as part of the SMTP import/export functionality). This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain...

CVSS:
2.7
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Nov 30, 2022

CVE-2022-45833 on NVD →

Easy WP SMTP <= 1.4.9 - Authenticated (Administrator+) PHP Object Injection

high

The Easy WP SMTP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 via deserialization of untrusted input when processing the contents of an imported file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin....

CVSS:
7.2
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Oct 10, 2022

CVE-2022-3334 on NVD →

Easy WP SMTP <= 1.4.2 - Sensitive Information Disclosure

high

The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The...

CVSS:
8.1
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Dec 7, 2020

CVE-2020-35234 on NVD →

Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update

critical

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings an...

CVSS:
9.8
Affected:
up to 1.3.9.1
Fixed in:
1.3.9.1
Disclosed:
Mar 17, 2019

CVE-2019-25141 on NVD →

Easy WP SMTP <= 1.2.4 - Cross-Site Scripting

medium

XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.

CVSS:
6.1
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Apr 14, 2017

CVE-2017-7723 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database