CVE · Critical

CVE-2019-25141 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25141 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Missing Authorization Critical 9.8 < 1.3.9.1 1.3.9.1 2019-03-17

CVE-2019-25141

The Easy WP SMTP plugin through version 1.3.9 contains an authorization bypass vulnerability stemming from absent capability verification in the admin_init() function combined with inadequate input sanitization. This flaw allows unauthenticated attackers to alter plugin configuration and other site options, potentially enabling them to create new administrator accounts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.