YaySMTP <= 2.6.6 - Authenticated (Administrator+) SQL Injection
medium
The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above...
- CVSS:
- 4.9
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Jun 27, 2025
CVE-2025-53256 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] <= 6.8.1 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows SQL Injection.This issue affects YaySMTP: from n/a through 2.6.5.
- Affected:
- up to 6.8.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2025
CVE-2025-53256 on NVD →
YaySMTP <= 2.6.4 - Authenticated (Administrator+) SQL Injection
medium
The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above...
- CVSS:
- 4.9
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.5
- Disclosed:
- May 7, 2025
CVE-2025-47587 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.6.5
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- May 7, 2025
CVE-2025-47587 on NVD →
YaySMTP 2.4.9 - 2.6.3 - Unauthenticated Stored Cross-Site Scripting
high
The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...
- CVSS:
- 7.2
- Affected:
- 2.4.9 – 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Feb 18, 2025
CVE-2025-0916 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.4.6
unknown
[en] The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenev...
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.6
- Disclosed:
- Jul 12, 2023
CVE-2023-3093 on NVD →
YaySMTP <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting via Email
high
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...
- CVSS:
- 7.2
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.6
- Disclosed:
- Jun 12, 2023
CVE-2023-3093 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.2.2
unknown
[en] The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Aug 8, 2022
CVE-2022-2372 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.2.1
unknown
[en] The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 8, 2022
CVE-2022-2371 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.2.1
unknown
[en] The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 1, 2022
CVE-2022-2369 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.2.1
unknown
[en] The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Aug 1, 2022
CVE-2022-2370 on NVD →
YaySMTP – Simple WP SMTP Mail <= 2.2 - Stored Cross-Site Scripting
medium
The YaySMTP – Simple WP SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[fromName]' parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with minimal permissions such a...
- CVSS:
- 6.4
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jul 18, 2022
CVE-2022-2371 on NVD →
YaySMTP – Simple WP SMTP Mail <= 2.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters, with at least one being the 'client_id' parameter, in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, administrator...
- CVSS:
- 5.5
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.2
- Disclosed:
- Jul 15, 2022
CVE-2022-2372 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] < 2.2.2
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress YaySMTP – Simple WP SMTP Mail plugin (versions <= 2.2.1).
Developer made an error and added version 1.6 as a patched version, but this version number was used by an older version.
Update the WordPress YaySMTP plugin to the latest a...
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Jul 14, 2022
YaySMTP – Simple WP SMTP Mail <= 2.2 - Sensitive Information Disclosure
high
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the logs of the plugin
- CVSS:
- 7.5
- Affected:
- 2.2 – 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Jul 11, 2022
CVE-2022-2369 on NVD →
YaySMTP – Simple WP SMTP Mail <= 2.2 - Missing Authorization to Sensitive Information Exposure
medium
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
- CVSS:
- 6.5
- Affected:
- up to 2.2
- Fixed in:
- 2.2.1
- Disclosed:
- Jul 11, 2022
CVE-2022-2370 on NVD →
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service [yaysmtp] >= 2.4.9 - < 2.6.4
unknown
- Affected:
- 2.4.9 – 2.6.4
- Fixed in:
- 2.6.4
CVE-2025-0916 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database