WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Easy Wp Smtp?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Easy Wp Smtp — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: easy-wp-smtp
  • 500000+ instalaciones activas

emailemail logsgmailoutlooksmtp

Estado de mantenimiento

  • Última versión conocida: 2.15.0
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

8 CVEs conocidos registrados para Easy Wp Smtp. Reportadas entre 2017 y 2024.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-3073 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1 Representación engañosa de información crítica en la interfaz de usuario Baja 2,7 < 2.3.1 2.3.1 2024-06-12 ✓ corregido en la última versión
CVE-2019-25141 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Falta de control de autorización Crítica 9,8 < 1.3.9.1 1.3.9.1 2023-06-07 ✓ corregido en la última versión
CVE-2022-45833 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,8 < 1.5.2 1.5.2 2022-11-30 ✓ corregido en la última versión
CVE-2022-45829 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,7 < 1.5.2 1.5.2 2022-11-30 ✓ corregido en la última versión
CVE-2022-42699 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Control incorrecto de la generación de código (inyección de código) Crítica 9,1 < 1.5.2 1.5.2 2022-11-30 ✓ corregido en la última versión
CVE-2022-3334 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0 Deserialización de datos no confiables Alta 7,2 < 1.5.0 1.5.0 2022-10-10 ✓ corregido en la última versión
CVE-2020-35234 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4 Inserción de información sensible en un archivo de registro (log) Alta 7,5 < 1.4.4 1.4.4 2020-12-07 ✓ corregido en la última versión
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.3 Desconocido < 1.4.3 1.4.3 2020-12-07 ✓ corregido en la última versión

CVE-2024-3073

The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers, with administrative-level access and above, to view the SMTP password for the supplied server. Although this would not be useful for attackers in most cases, if an administrator account becomes compromised this could be useful information to an attacker in a limited environment.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2019-25141

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2022-45833

The Easy WP SMTP plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.5.1 possibly via the 'admin_init' function (as part of the SMTP import/export functionality). This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-45829

The Easy WP SMTP plugin for WordPress is vulnerable to Arbitrary File Deletion versions up to, and including, 1.5.1. This is possibly due to the SMTP import/export functionality. This makes it possible for administrator-level attackers to arbitrarily delete files on the server, including critical files for the website's functionality.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-42699

The Easy WP SMTP plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.5.1 possibly via the 'admin_init' function (as part of the SMTP import/export functionality). This allows administrator-level attackers to execute code on the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-3334

The Easy WP SMTP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 via deserialization of untrusted input when processing the contents of an imported file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2020-35234

The plugin has an optional debug log file generated with a random name, located in the plugin folder and which contains all email messages sent. However, this folder does not have any index page, allowing access to log file on servers with the directory listing enabled or misconfigured. This could allow attackers to gain unauthorised access to the blog by reseting the admin password by getting the reset link from the log.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.3

Unauthenticated Admin Password Reset vulnerability found by mathieg2 in WordPress Easy WP SMTP plugin (versions <= 1.4.2).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 7 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Desconocido < 1.3.9.1 1.3.9.1 2019-03-20 ✓ corregido en la última versión
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Desconocido < 1.3.9.1 1.3.9.1 2019-03-17 ✓ corregido en la última versión
CVE-2017-7723 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.2.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 1.2.5 1.2.5 2017-04-14 ✓ corregido en la última versión
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Desconocido < 1.5.2 1.5.2 ✓ corregido en la última versión
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Desconocido < 1.5.2 1.5.2 ✓ corregido en la última versión
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Desconocido < 1.5.2 1.5.2 ✓ corregido en la última versión
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Desconocido < 1.3.9.1 1.3.9.1 ✓ corregido en la última versión

Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1

Unauthenticated arbitrary "wp_options" import vulnerability found Jerome Bruandet in WordPress Easy WP SMTP plugin (versions <= 1.3.9).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2017-7723

XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2

Update the WordPress Easy WP SMTP plugin to the latest available version (at least 1.5.2). TomS discovered and reported this Arbitrary File Deletion vulnerability in WordPress Easy WP SMTP Plugin. This could allow a malicious actor to delete files from your website. If core files are deleted from your website, it could cause your site to break and stop functioning. This vulnerability has been fixed in version 1.5.2.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2

Update the WordPress Easy WP SMTP plugin to the latest available version (at least 1.5.2). TomS discovered and reported this Remote Code Execution (RCE) vulnerability in WordPress Easy WP SMTP Plugin. This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website. This vulnerability has been fixed in version 1.5.2.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2

Update the WordPress Easy WP SMTP plugin to the latest available version (at least 1.5.2). TomS discovered and reported this Directory Traversal vulnerability in WordPress Easy WP SMTP Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 1.5.2.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Cómo solucionarlo

Mantén Easy Wp Smtp actualizado — 2.15.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.