S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2019-25141 Scanner

CVE-2019-25141 Scanner - Missing Authorization vulnerability in Easy WP SMTP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-25141
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and moreby smub
AFFECTED< 1.3.9.1SAFE ✓≥ 1.3.9.1
Updated Aug 21, 2026View on NVD →
Detail

The Easy WP SMTP plugin is widely used by WordPress website administrators to facilitate the sending of emails through an SMTP server. It enables users to configure email settings conveniently from the WordPress dashboard. Website administrators often rely on such plugins for securing and managing their outbound communication. This plugin is particularly popular for its user-friendly interface and effective integration with various SMTP providers. By addressing behind-the-scenes email delivery, it supports web developers and site managers in maintaining smooth communication flows. Unfortunately, vulnerabilities in these plugins can lead to severe security breaches if not patched swiftly.

The vulnerability detected in the Easy WP SMTP plugin is an authorization bypass, which is present in versions up to 1.3.9. Due to missing capability checks within the admin_init() function, unauthorized users can access and modify plugin settings. This missing authorization allows attackers to edit arbitrary options within the plugin. Such unauthorized changes may include injecting new administrative user accounts, posing a serious security risk. This vulnerability stems from improper input validation, making sites vulnerable to malicious exploitation.

The technical details of this vulnerability reveal that the issue arises from insufficient checks on the admin_init() function. Attackers exploit this by sending specifically crafted HTTP POST requests to the /wp-admin/admin-ajax.php endpoint. Parameters like "swpsmtp_import_settings" and "swpsmtp_import_settings_file" can be manipulated by the attacker to modify plugin settings. Successful exploitation includes changing user registration settings to allow the creation of users with administrative privileges. The HTTP status code 302 and location header responses are indicative of a successful attack attempt. This sets the stage for a harmful compromise of the website's user management system.

Exploitation of this vulnerability can lead to catastrophic effects, such as unauthorized control over the website. Attackers could create or alter admin-level user accounts, bypassing all standard authentication mechanisms. They might manipulate content, inject malicious scripts, or extract sensitive user information. This could result in data breaches, service disruptions, and loss of user trust. Ultimately, this could damage the website’s reputation and lead to financial losses if not addressed promptly.

REFERENCES

Solution Advice
  • Update Easy WP SMTP to the latest version where the vulnerability is patched.
  • Enhance plugin security by implementing additional capability checks within administrative functions.
  • Regularly audit website plugins and configurations for potential security flaws.
  • Monitor HTTP requests for unusual patterns that could indicate exploitation attempts.
  • Restrict access to critical plugin files and paths using server configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.