What the vulnerability does
01Description
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
What the vulnerability does
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
Explanation of Vulnerability in Simple Terms
Easy WP SMTP versions up to 1.5.1 contain a path traversal vulnerability that allows high-privilege users to read, modify, or delete arbitrary files on the server. An attacker with admin or equivalent access can exploit this to compromise site integrity and availability. The vulnerability affects the file handling mechanism without requiring user interaction.
What an attacker can do
Read, modify, or delete arbitrary files on the server.
Potential impact on your site
A compromised admin account can be used to alter or destroy site files, causing data loss or site takeover.
Conditions required to exploit
Attacker must have high-level privileges (admin or equivalent) on the WordPress site.
Key dates
External resources
Related vulnerabilities