WordPress Plugin Vulnerabilities

Easy WP SMTP < 1.4.3 - Debug Log Disclosure

Description

The plugin has an optional debug log file generated with a random name, located in the plugin folder and which contains all email messages sent. However, this folder does not have any index page, allowing access to log file on servers with the directory listing enabled or misconfigured. This could allow attackers to gain unauthorised access to the blog by reseting the admin password by getting the reset link from the log.

Affects Plugins

Fixed in 1.4.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Jerome Bruandet (nintechnet)
Verified
No

Timeline

Publicly Published
2020-12-07 (about 2 years ago)
Added
2020-12-07 (about 2 years ago)
Last Updated
2020-12-15 (about 2 years ago)

Other