← back
CVE-2019-25141criticalobserved exploitationCWE-862

Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 4.5%
from disclosure to weapon
Published on NVDJun 7
VulnCheckJul 23
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
yesVulnCheck
In short

The Easy WP SMTP plugin for WordPress allows unauthenticated attackers to change plugin settings and site options without logging in, which can be exploited to create fake admin accounts. This is a critical flaw because anyone on the internet can take control of the website.

Technical detail

The plugin's admin_init() function lacks capability checks and input validation, allowing unauthenticated POST requests to modify arbitrary WordPress options. An attacker can inject new administrative user accounts or alter site configuration without authentication, leading to complete site compromise.

Summary generated and translated by AI from the official description.
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H