Account Takeover Vulnerability in Easy WP SMTP Plugin for WordPress
CVE-2020-35234
What is CVE-2020-35234?
The Easy WP SMTP plugin for WordPress prior to version 1.4.4 is susceptible to an account takeover vulnerability. If an attacker gains access to the directory containing the plugin, they can locate sensitive log files that reveal password-reset links. By exploiting this flaw, an attacker could initiate a reset of an administrator's password using a link found in these logs, effectively allowing them to take over the administrator account. This vulnerability was actively exploited in the wild in December 2020, emphasizing the importance of promptly updating to the latest version to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
75% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved