VYPR

SMTP

by Bestwebsoft

CVEs (3)

  • CVE-2024-13908HigMar 8, 2025
    risk 0.40cvss 7.2epss 0.01

    The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2017-18518MedAug 20, 2019
    risk 0.40cvss 6.1epss 0.02

    The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.

  • CVE-2017-2171MedMay 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom…