Easy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UI
Summary
| CVE | CVE-2024-3073 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-06-13 09:15:13 UTC |
| Updated | 2026-04-08 19:21:15 UTC |
| Description | The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers, with administrative-level access and above, to view the SMTP password for the supplied server. Although this would not be useful for attackers in most cases, if an administrator account becomes compromised this could be useful information to an attacker in a limited environment. |
Risk And Classification
Primary CVSS: v3.1 2.7 LOW from [email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.002530000 probability, percentile 0.486550000 (date 2026-04-13)
Problem Types: CWE-257 | NVD-CWE-noinfo | CWE-257 CWE-257 Storing Passwords in a Recoverable Format
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 2.7 | LOW | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | DECLARED | 2.7 | LOW | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wp-ecommerce | Easy Wp Smtp | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Smub | Easy WP SMTP WordPress SMTP And Email Logs Gmail Office 365 Outlook Custom SMTP And More | affected 2.3.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.wordfence.com/threat-intel/vulnerabilities/id/b043197c-4477-4663-abb8-58401... | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| plugins.trac.wordpress.org/changeset | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Andy Gilbert (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-06-12T20:02:54.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.