CVE Database /
CVE-2019-25141
CVE · Critical
CVE-2019-25141 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-25141
|
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 |
Missing Authorization |
Critical
9.8
|
< 1.3.9.1
|
1.3.9.1 |
2019-03-17 |
—
|
CVE-2019-25141
The Easy WP SMTP plugin through version 1.3.9 contains an authorization bypass vulnerability stemming from absent capability verification in the admin_init() function combined with inadequate input sanitization. This flaw allows unauthenticated attackers to alter plugin configuration and other site options, potentially enabling them to create new administrator accounts.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings