VendorsWP eCommerceeasy_wp_smtpall versions
Vulnerabilities

WP eCommerce Easy WP SMTP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2019-25141
Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update
Published 2023-06-07 · Modified
9.8EPSS 0.045
CVE-2022-42699
WordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Remote Code Execution (RCE)
Published 2022-12-06 · Modified
9.1EPSS 0.014
CVE-2022-45829
WordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Arbitrary File Deletion
Published 2022-12-06 · Modified
8.7EPSS 0.009
CVE-2020-35234
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.
Published 2020-12-14 · Modified
7.5EPSS 0.646
CVE-2022-3334
Easy WP SMTP < 1.5.0 - Admin+ PHP Objection Injection
Published 2022-10-31 · Modified
7.2EPSS 0.012
CVE-2022-45833
WordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Directory Traversal
Published 2022-12-06 · Modified
6.8EPSS 0.008
CVE-2017-7723
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.
Published 2017-04-24 · Modified
6.1EPSS 0.008
CVE-2024-3073
Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UI
Published 2024-06-13 · Modified
2.7EPSS 0.003