Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UI
low
The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated att...
- CVSS:
- 2.7
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jun 12, 2024
CVE-2024-3073 on NVD →
Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Remote Code Execution
high
The Easy WP SMTP plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.5.1 possibly via the 'admin_init' function (as part of the SMTP import/export functionality). This allows administrator-level attackers to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Nov 30, 2022
CVE-2022-42699 on NVD →
Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Arbitrary File Deletion
medium
The Easy WP SMTP plugin for WordPress is vulnerable to Arbitrary File Deletion versions up to, and including, 1.5.1. This is possibly due to the SMTP import/export functionality. This makes it possible for administrator-level attackers to arbitrarily delete files on the server, including critical files for the website'...
- CVSS:
- 6.5
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Nov 30, 2022
CVE-2022-45829 on NVD →
Easy WP SMTP <= 1.5.1 - Authenticated (Admin+) Directory Traversal
low
The Easy WP SMTP plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.5.1 possibly via the 'admin_init' function (as part of the SMTP import/export functionality). This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 2.7
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Nov 30, 2022
CVE-2022-45833 on NVD →
Easy WP SMTP <= 1.4.9 - Authenticated (Administrator+) PHP Object Injection
high
The Easy WP SMTP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 via deserialization of untrusted input when processing the contents of an imported file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin....
- CVSS:
- 7.2
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Oct 10, 2022
CVE-2022-3334 on NVD →
Easy WP SMTP <= 1.4.2 - Sensitive Information Disclosure
high
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The...
- CVSS:
- 8.1
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Dec 7, 2020
CVE-2020-35234 on NVD →
Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update
critical
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings an...
- CVSS:
- 9.8
- Affected:
- up to 1.3.9.1
- Fixed in:
- 1.3.9.1
- Disclosed:
- Mar 17, 2019
CVE-2019-25141 on NVD →
Easy WP SMTP <= 1.2.4 - Cross-Site Scripting
medium
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.
- CVSS:
- 6.1
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Apr 14, 2017
CVE-2017-7723 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database