Description
The WordPress Easy WP SMTP Plugin has its log folder remotely accessible and its content available for access.
The WordPress Easy WP SMTP Plugin has its log folder remotely accessible and its content available for access.
id: CVE-2020-35234
info:
name: SMTP WP Plugin Directory Listing
author: PR3R00T
severity: high
description: The WordPress Easy WP SMTP Plugin has its log folder remotely accessible and its content available for access.
impact: |
Low: Information disclosure
remediation: Upgrade to version 1.4.3 or newer and consider disabling debug logs.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2020-35234
- https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/
- https://wordpress.org/plugins/easy-wp-smtp/#developers
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2020-35234
cwe-id: CWE-532
epss-score: 0.64603
epss-percentile: 0.99198
cpe: cpe:2.3:a:wp-ecommerce:easy_wp_smtp:*:*:*:*:*:wordpress:*:*
metadata:
max-request: 2
vendor: wp-ecommerce
product: easy_wp_smtp
framework: wordpress
tags: cve2020,cve,wordpress,wp-plugin,smtp,wp-ecommerce,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp-content/plugins/easy-wp-smtp/"
- "{{BaseURL}}/wp-content/plugins/wp-mail-smtp-pro/"
matchers:
- type: word
words:
- "debug"
- "log"
- "Index of"
condition: and
# digest: 4a0a00473045022100cf6063484d8353ecd228cc097adce8796c02e96e33cdd915b47b3a975260c88a02203e61fb955c719b384c99abfb56744e90ea54696291d3cf485e1b8be3267b6927:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.