Vulnerabilities > WP Ecommerce > Easy WP Smtp > High

DATE CVE VULNERABILITY TITLE RISK
2022-12-06 CVE-2022-42699 Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp
Auth.
network
low complexity
wp-ecommerce
8.8
2022-12-06 CVE-2022-45829 Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp
Auth.
network
low complexity
wp-ecommerce
8.1
2022-10-31 CVE-2022-3334 Unspecified vulnerability in Wp-Ecommerce Easy WP Smtp
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
network
low complexity
wp-ecommerce
7.2
2020-12-14 CVE-2020-35234 Information Exposure Through Log Files vulnerability in Wp-Ecommerce Easy WP Smtp
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.
network
low complexity
wp-ecommerce CWE-532
7.5