Vulnerabilities > WP Ecommerce > Easy WP Smtp
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-07 | CVE-2019-25141 | Missing Authorization vulnerability in Wp-Ecommerce Easy WP Smtp The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. | 9.8 |
2022-12-06 | CVE-2022-42699 | Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp Auth. | 8.8 |
2022-12-06 | CVE-2022-45829 | Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp Auth. | 8.1 |
2022-12-06 | CVE-2022-45833 | Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp Auth. | 6.5 |
2022-10-31 | CVE-2022-3334 | Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | 7.2 |
2020-12-14 | CVE-2020-35234 | Information Exposure Through Log Files vulnerability in Wp-Ecommerce Easy WP Smtp The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. | 7.5 |
2017-04-24 | CVE-2017-7723 | Cross-site Scripting vulnerability in Wp-Ecommerce Easy WP Smtp XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body. | 6.1 |