Recursos /
Plugins de WordPress /
SureMail
SEGURIDAD DE PLUGINS
¿Es seguro SureMail?
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
Qué hace este plugin
- Slug:
suremails
- Autor: Brainstorm Force
- 200000+ instalaciones activas
- 96/100 calificación (23 reseñas en wordpress.org)
- 1576343 descargas totales
- En WordPress.org desde 2025-01-22
emailemail logsgmail smtpoutlooksmtp
Estado de mantenimiento
- Última actualización: 2026-07-14 5:23am GMT
- Probado hasta WordPress: 7.0.2
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
1 CVE conocido registrado para SureMail.
Reportadas entre 2025 y 2025.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-13516
|
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers [suremails] < 1.9.1 |
Carga de archivos sin restricción de tipo peligroso |
Alta
8,1
|
< 1.9.1
|
1.9.1 |
2025-12-01 |
—
|
CVE-2025-13516
The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessible directory (wp-content/uploads/suremails/attachments/) without validating file extensions or content types. Files are saved with predictable names derived from MD5 hashes of their content. While the plugin attempts to protect this directory with an Apache .htaccess file to disable PHP execution, this protection is ineffective on nginx, IIS, and Lighttpd servers, or on misconfigured Apache installations. This makes it possible for unauthenticated attackers to achieve Remote Code Execution by uploading malicious PHP files through any public form that emails attachments, calculating the predictable filename, and directly accessing the file to execute arbitrary code granted they are exploiting a site running on an affected web server configuration.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas
Verifica tu propio sitio WordPress
Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.