Vulnerabilities > WP Ecommerce > Easy WP Smtp > 1.3.9.3

DATE CVE VULNERABILITY TITLE RISK
2022-12-06 CVE-2022-42699 Code Injection vulnerability in Wp-Ecommerce Easy WP Smtp
Auth.
network
low complexity
wp-ecommerce CWE-94
8.8
2022-12-06 CVE-2022-45829 Path Traversal vulnerability in Wp-Ecommerce Easy WP Smtp
Auth.
network
low complexity
wp-ecommerce CWE-22
8.1
2022-12-06 CVE-2022-45833 Path Traversal vulnerability in Wp-Ecommerce Easy WP Smtp
Auth.
network
low complexity
wp-ecommerce CWE-22
6.5
2022-10-31 CVE-2022-3334 Deserialization of Untrusted Data vulnerability in Wp-Ecommerce Easy WP Smtp
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
network
low complexity
wp-ecommerce CWE-502
7.2