WordPress Plugin Vulnerabilities
Easy WP SMTP < 1.4.3 - Debug Log Disclosure
Description
The plugin has an optional debug log file generated with a random name, located in the plugin folder and which contains all email messages sent. However, this folder does not have any index page, allowing access to log file on servers with the directory listing enabled or misconfigured. This could allow attackers to gain unauthorised access to the blog by reseting the admin password by getting the reset link from the log.
Affects Plugins
References
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jerome Bruandet (nintechnet)
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-12-07 (about 2 years ago)
Added
2020-12-07 (about 2 years ago)
Last Updated
2020-12-15 (about 2 years ago)