PLUGIN SECURITY
Is Easy Wp Smtp safe?
Make SMTP email sending and delivery easy. Configure Gmail SMTP, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
What this plugin does
- Slug:
easy-wp-smtp - Author: Syed Balkhi
- 500000+ active installs
- 92/100 rating (707 reviews on wordpress.org)
- 14647153 all-time downloads
- On WordPress.org since 2013-04-17
emailemail logsgmailoutlooksmtp
Maintenance status
- Latest known version: 2.15.0
- Last updated: 2026-08-12 9:18am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
8 known CVEs on file for Easy Wp Smtp. Reported between 2017 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-3073 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1 | User Interface (UI) Misrepresentation of Critical Information | Low 2.7 | < 2.3.1 | 2.3.1 | 2024-06-12 | ✓ fixed in latest |
| CVE-2022-45833 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.8 | < 1.5.2 | 1.5.2 | 2022-11-30 | ✓ fixed in latest |
| CVE-2022-45829 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.7 | < 1.5.2 | 1.5.2 | 2022-11-30 | ✓ fixed in latest |
| CVE-2022-42699 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 | Improper Control of Generation of Code ('Code Injection') | Critical 9.1 | < 1.5.2 | 1.5.2 | 2022-11-30 | ✓ fixed in latest |
| CVE-2022-3334 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0 | Deserialization of Untrusted Data | High 7.2 | < 1.5.0 | 1.5.0 | 2022-10-10 | ✓ fixed in latest |
| CVE-2020-35234 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4 | Insertion of Sensitive Information into Log File | High 7.5 | < 1.4.4 | 1.4.4 | 2020-12-07 | ✓ fixed in latest |
| — | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.3 | — | Unknown | < 1.4.3 | 1.4.3 | 2020-12-07 | ✓ fixed in latest |
| — | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 | — | Unknown | < 1.3.9.1 | 1.3.9.1 | 2019-03-20 | ✓ fixed in latest |
+ 7 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2019-25141 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 | Missing Authorization | Critical 9.8 | < 1.3.9.1 | 1.3.9.1 | 2019-03-17 | ✓ fixed in latest |
| CVE-2017-7723 | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.2.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.2.5 | 1.2.5 | 2017-04-14 | ✓ fixed in latest |
| — | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 | — | Unknown | < 1.5.2 | 1.5.2 | — | ✓ fixed in latest |
| — | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 | — | Unknown | < 1.5.2 | 1.5.2 | — | ✓ fixed in latest |
| — | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 | — | Unknown | < 1.5.2 | 1.5.2 | — | ✓ fixed in latest |
| — | Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 | — | Unknown | < 1.3.9.1 | 1.3.9.1 | — | ✓ fixed in latest |
| CVE-2019-25141 | Easy WP SMTP <= 1.3.9 - Unauthenticated Arbitrary wp_options Import | — | Unknown | < 1.3.9.1 | 1.3.9.1 | — | ✓ fixed in latest |
How to fix it
Keep Easy Wp Smtp updated — 2.15.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin — 4000000+ active installs — 96/100 (5181) — max PHP 8.4
- MC4WP: Mailchimp for WordPress — 1000000+ active installs — 96/100 (1496) — max PHP 8.4
- Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App — 300000+ active installs — 94/100 (525) — max PHP 8.4
- WP Mail Logging — 300000+ active installs — 94/100 (365)
- Mailchimp for WooCommerce — 200000+ active installs — 80/100 (725) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.