CVE · Low

CVE-2024-3073 — Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3073 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1 User Interface (UI) Misrepresentation of Critical Information Low 2.7 < 2.3.1 2.3.1 2024-06-12

CVE-2024-3073

The Easy WP SMTP by SendLayer plugin for WordPress through version 2.3.0 exposes SMTP credentials by displaying the server password directly in the settings interface. Administrators with access to plugin settings can view the plaintext SMTP password, which poses a risk if an admin account is compromised, potentially allowing attackers to access email infrastructure in certain scenarios. The vulnerability requires authenticated administrative access to exploit but could facilitate lateral movement or credential harvesting in compromised environments.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.