CVE · High

CVE-2022-3334 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3334 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0 Deserialization of Untrusted Data High 7.2 < 1.5.0 1.5.0 2022-10-10

CVE-2022-3334

The Easy WP SMTP plugin for WordPress through version 1.4.9 contains a PHP Object Injection vulnerability that occurs when deserializing data from imported files, potentially allowing administrators to inject malicious PHP objects. While the plugin itself lacks a Property-Oriented Programming chain to execute attacks, the presence of such a chain in other installed plugins or themes could enable attackers to execute arbitrary code, access sensitive information, or delete files. The vulnerability was patched in version 1.5.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.