VYPR

Wp Mail SMTP

by Wpforms

CVEs (2)

  • CVE-2023-3213MedOct 4, 2023
    risk 0.34cvss 5.3epss 0.00

    The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive…

  • CVE-2024-6694LowJul 20, 2024
    risk 0.11cvss 2.7epss 0.01

    The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated attackers,…