Easy WP SMTP <= 1.4.2 - Sensitive Information Disclosure
2020-12-07 00:00
AnonymousStrategic Overview
StatusPatched in 1.4.3
Affected PluginEasy WP SMTP – WordPress SMTP and Email Logs: Gmail SMTP, Office 365, Outlook, Custom SMTP, and more
Affected Version
<= 1.4.2CVSS8.1High
CVE
CVE-2020-35234Vulnerability Overview
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.
Technical Analysis
REMEDIATION: Update to version 1.4.3, or a newer patched version --- IDENTIFIER: CWE-532 (Insertion of Sensitive Information into Log File) The product writes sensitive information to a log file.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C