CVE-2019-25141
Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update
Record summary
CVE-2019-25141 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 23, 2014 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 26, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and moreBrowse smub / Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and moreDefault status: unaffected | CVE List | Before 1.3.9.1 | affected |
easy_wp_smtpBrowse wp-ecommerce / easy_wp_smtp | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALEasy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options UpdateCVSS 9.8
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.
Impact
Unauthenticated attackers can modify plugin settings and arbitrary site options to inject new administrative user accounts, leading to complete WordPress site takeover.
Remediation
Upgrade to Easy WP SMTP version 1.4.0 or later.
Source: ProjectDiscovery