PLUGIN SECURITY

Is Easy Wp Smtp safe?

Make SMTP email sending and delivery easy. Configure Gmail SMTP, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.

What this plugin does

  • Slug: easy-wp-smtp
  • Author: Syed Balkhi
  • 500000+ active installs
  • 92/100 rating (707 reviews on wordpress.org)
  • 14647153 all-time downloads
  • On WordPress.org since 2013-04-17

emailemail logsgmailoutlooksmtp

Maintenance status

  • Latest known version: 2.15.0
  • Last updated: 2026-08-12 9:18am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

8 known CVEs on file for Easy Wp Smtp. Reported between 2017 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3073 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 2.3.1 User Interface (UI) Misrepresentation of Critical Information Low 2.7 < 2.3.1 2.3.1 2024-06-12 ✓ fixed in latest
CVE-2022-45833 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.8 < 1.5.2 1.5.2 2022-11-30 ✓ fixed in latest
CVE-2022-45829 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.7 < 1.5.2 1.5.2 2022-11-30 ✓ fixed in latest
CVE-2022-42699 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Improper Control of Generation of Code ('Code Injection') Critical 9.1 < 1.5.2 1.5.2 2022-11-30 ✓ fixed in latest
CVE-2022-3334 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.0 Deserialization of Untrusted Data High 7.2 < 1.5.0 1.5.0 2022-10-10 ✓ fixed in latest
CVE-2020-35234 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.4 Insertion of Sensitive Information into Log File High 7.5 < 1.4.4 1.4.4 2020-12-07 ✓ fixed in latest
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.4.3 Unknown < 1.4.3 1.4.3 2020-12-07 ✓ fixed in latest
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Unknown < 1.3.9.1 1.3.9.1 2019-03-20 ✓ fixed in latest
+ 7 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25141 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Missing Authorization Critical 9.8 < 1.3.9.1 1.3.9.1 2019-03-17 ✓ fixed in latest
CVE-2017-7723 Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.2.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.2.5 1.2.5 2017-04-14 ✓ fixed in latest
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Unknown < 1.5.2 1.5.2 ✓ fixed in latest
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Unknown < 1.5.2 1.5.2 ✓ fixed in latest
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.5.2 Unknown < 1.5.2 1.5.2 ✓ fixed in latest
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more [easy-wp-smtp] < 1.3.9.1 Unknown < 1.3.9.1 1.3.9.1 ✓ fixed in latest
CVE-2019-25141 Easy WP SMTP <= 1.3.9 - Unauthenticated Arbitrary wp_options Import Unknown < 1.3.9.1 1.3.9.1 ✓ fixed in latest

How to fix it

Keep Easy Wp Smtp updated — 2.15.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.