CVE Database /
CVE-2022-3334
CVE · High
CVE-2022-3334 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3334
|
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0 |
Deserialization of Untrusted Data |
High
7.2
|
< 1.5.0
|
1.5.0 |
2022-10-10 |
—
|
CVE-2022-3334
The Easy WP SMTP plugin for WordPress through version 1.4.9 contains a PHP Object Injection vulnerability that occurs when deserializing data from imported files, potentially allowing administrators to inject malicious PHP objects. While the plugin itself lacks a Property-Oriented Programming chain to execute attacks, the presence of such a chain in other installed plugins or themes could enable attackers to execute arbitrary code, access sensitive information, or delete files. The vulnerability was patched in version 1.5.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings