Easy Wp Smtp
Vendor:
First CVE: Apr 24, 2017 · Active for 9 years
8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Easy Wp Smtp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2017
9 years ago
Most Recent CVE
Jun 13, 2024
775 days ago
CVE Severity & Scoring
Easy Wp Smtp8 CVEs
13%
25%
50%
13%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low3 (37.5%)
High2 (25.0%)
None3 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35234HIGH The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/ | Dec 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2019-25141CRITICAL The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() fu | Jun 7, 2023 | 9.8 | 41 | NO | YES |
CVE-2022-42699HIGH Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | Dec 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-45829HIGH Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. | Dec 6, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-3334HIGH The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or n | Oct 31, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-45833MEDIUM Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | Dec 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2017-7723MEDIUM XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body. | Apr 24, 2017 | 6.1 | 17 | NO | NO |
The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is | Jun 13, 2024 | 2.7 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
2 CVEs
25.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Easy Wp Smtp
Top CWEs
Versions
No cataloged versions.