Lucene search

K
wpvulndbWpvulndbWPVDB-ID:E033A769-AF90-4AD9-BEF1-C8B561D2E2B3
HistoryNov 30, 2022 - 12:00 a.m.

Easy WP SMTP < 1.5.2 - Admin+ Arbitrary File Access

2022-11-3000:00:00
wpscan.com
10
easy wp smtp
arbitrary file access
user input validation
high privilege users
path traversal

EPSS

0.001

Percentile

28.8%

The plugin does not validate some user input used to generate paths, which could allow high privilege users such as admin to access arbitrary files (even when they should not be able to, for example in multisite) via a traversal attack

EPSS

0.001

Percentile

28.8%

Related for WPVDB-ID:E033A769-AF90-4AD9-BEF1-C8B561D2E2B3