S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-35234 Scanner

CVE-2020-35234 scanner - Account Takeover vulnerability in Easy WP SMTP plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-35234
7.5
CVSS

The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Easy WP SMTP is a popular plugin used by WordPress website owners to simplify their email delivery process. With over 500,000 active installations, the Easy WP SMTP plugin provides a convenient way for users to set up their SMTP server and handle their outgoing WordPress emails. 

Recently, a critical vulnerability has been detected in this plugin. The vulnerability is identified as CVE-2020-35234, which allows an attacker to take over the Administrator account. If an attacker can access the wp-content/plugins/easy-wp-smtp/ directory, they can obtain a log file that logs all password-reset links. It means that the attacker can reset the Administrator password and gain unauthorized access to the website.

When CVE-2020-35234 is exploited, it can lead to significant security risks for the website owner. An attacker who has taken over the Administrator account can completely compromise the website, take control of sensitive data, and misuse all the features of the website. The attacker can not only damage the reputation and credibility of the website but can also cause financial damage to the owner.

In conclusion, website owners must be aware of the vulnerabilities present in the tools they use and must take necessary precautions to secure their digital assets. With the pro features offered by s4e.io, it becomes easier to learn about vulnerabilities and ways to protect websites. By subscribing to the platform, users can prevent attacks and keep their websites safe from security breaches.

 

REFERENCES

Solution Advice

To protect against CVE-2020-35234, users can take precautions by implementing these actions:

  • Update the Easy WP SMTP plugin to the latest version (1.4.4) immediately.
  • Install a reliable security plugin to monitor the website continuously and identify vulnerabilities.
  • Use strong and unique passwords to avoid password guessing.
  • Enable two-factor authentication on the website.
  • Regular backup of the website's database so that if something goes wrong, the data can be quickly restored.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-35234 scanner - Account Takeover vulnerability in Easy WP SMTP plugin for WordPress | S4E