QID 150624
Date Published: 2022-12-15
QID 150624: WordPress Easy WP SMTP Plugin: Multiple Vulnerabilities (CVE-2022-42699,CVE-2022-45833,CVE-2022-45829)
Easy WP SMTP is a WordPress plugin which allows users to configure and send all outgoing emails via a SMTP server.
Easy WP SMTP contains multiple vulnerabilities:
CVE-2022-42699: Authenticated Remote Code Execution vulnerability
CVE-2022-45833: Authenticated Path Traversal vulnerability
CVE-2022-45829: Authenticated Path Traversal vulnerability
Affected versions:
Easy WP SMTP prior to version 1.5.2
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of the vulnerability may allow remote attackers to read sensitive files or execute arbitrary code on the target system.
Solution
Customers are advised to upgrade to Easy WP SMTP 1.5.2 or later to remediate this vulnerability.
Vendor References
- CVE-2022-42699 -
patchstack.com/database/vulnerability/easy-wp-smtp/wordpress-easy-wp-smtp-plugin-1-5-1-auth-remote-code-execution-rce-vulnerability?_s_id=cve - CVE-2022-45829 -
patchstack.com/database/vulnerability/easy-wp-smtp/wordpress-easy-wp-smtp-plugin-1-5-1-auth-arbitrary-file-deletion-vulnerability?_s_id=cve - CVE-2022-45833 -
patchstack.com/database/vulnerability/easy-wp-smtp/wordpress-easy-wp-smtp-plugin-1-5-1-auth-arbitrary-file-read-vulnerability?_s_id=cve
CVEs related to QID 150624
Software Advisories