CVE Database /
CVE-2024-3073
CVE · Low
CVE-2024-3073 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3073
|
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1 |
User Interface (UI) Misrepresentation of Critical Information |
Low
2.7
|
< 2.3.1
|
2.3.1 |
2024-06-12 |
—
|
CVE-2024-3073
The Easy WP SMTP by SendLayer plugin for WordPress through version 2.3.0 exposes SMTP credentials by displaying the server password directly in the settings interface. Administrators with access to plugin settings can view the plaintext SMTP password, which poses a risk if an admin account is compromised, potentially allowing attackers to access email infrastructure in certain scenarios. The vulnerability requires authenticated administrative access to exploit but could facilitate lateral movement or credential harvesting in compromised environments.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings