CVE · Low

CVE-2024-6694 — WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6694 WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin [wp-mail-smtp] < 4.1.0 Storing Passwords in a Recoverable Format Low 2.7 < 4.1.0 4.1.0 2024-07-19

CVE-2024-6694

The WP Mail SMTP plugin for WordPress contains a security flaw that allows unauthorized users with administrative access or higher to obtain sensitive email password information when viewing the plugin's settings page. This vulnerability affects all versions of the plugin up to and including 4.0.1, potentially providing valuable credentials to an attacker in specific scenarios where administrator accounts are compromised.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.