Authorization Bypass Vulnerability in Easy WP SMTP Plugin for WordPress
CVE-2019-25141
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2019-25141?
The Easy WP SMTP plugin for WordPress has a vulnerability that allows unauthenticated attackers to bypass authorization due to missing capability checks within the admin_init() function. This oversight can lead to inadequate input validation, enabling these attackers to alter the plugin’s settings and inject unauthorized administrative user accounts, compromising the security of the entire site.
Affected Version(s)
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more 0 < 1.3.9.1