QID 150599
Date Published: 2022-11-28
QID 150599: WordPress Easy WP SMTP Plugin: PHP Object Injection Vulnerability (CVE-2022-3334)
Easy WP SMTP is a WordPress plugin which allows users to configure and send all outgoing emails via a SMTP server.
Affected versions of Easy WP SMTP plugin unserialises the content of an imported file, which could lead to PHP object injection issue when an admin imports a malicious file and a suitable gadget chain is present on the blog.
Affected versions:
Easy WP SMTP prior to version 1.5.0
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could an attacker to compromise Confidentiality, Integrity and Availability of the target application.
Solution
Customers are advised to upgrade to Easy WP SMTP 1.5.0 or later to remediate this vulnerability. For more information regarding this vulnerability please refer WPScan Advisory
Vendor References
- WPScan Advisory -
wpscan.com/vulnerability/0e735502-eaa2-4047-949e-bc8eb6b39fc9
CVEs related to QID 150599
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Easy WP SMTP Downloads |
|