CVE Database /
CVE-2020-35234
CVE · High
CVE-2020-35234 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-35234
|
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4 |
Insertion of Sensitive Information into Log File |
High
7.5
|
< 1.4.4
|
1.4.4 |
2020-12-07 |
—
|
CVE-2020-35234
Easy WP SMTP versions prior to 1.4.4 create optional debug log files with randomly generated names in the plugin directory that contain full email message contents. When server configurations permit directory listing, attackers can browse and access these logs to retrieve password reset links, potentially enabling unauthorized admin account takeover.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings