CVE · High

CVE-2020-35234 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35234 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4 Insertion of Sensitive Information into Log File High 7.5 < 1.4.4 1.4.4 2020-12-07

CVE-2020-35234

Easy WP SMTP versions prior to 1.4.4 create optional debug log files with randomly generated names in the plugin directory that contain full email message contents. When server configurations permit directory listing, attackers can browse and access these logs to retrieve password reset links, potentially enabling unauthorized admin account takeover.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.