โ† Back to browse ยท API

CVE-2019-25141

Severity
CRITICAL
CVSS
9.8
EPSS
0.04498
Risk score
40.77
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2019-11575, GHSA-RPX2-WVXR-QVRR
Products
smub:Easy WP SMTP โ€“ WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more 0 <1.3.9.1
Sources
euvd EUVD-2019-11575

Description

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.

References