Extension WordPress

Vulnérabilités FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

Cette page rassemble les failles publiées pour FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

5 fiches

CVE-2025-24739 Moyenne · 4,3
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

FluentSMTP <= 2.2.80 – Cross-Site Request Forgery

The FluentSMTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.80. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.2.80

Correctif

2.2.81

Publication

24/01/2025

CVE-2024-9511 Critique · 9,8
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider <= 2.2.82 – Unauthenticated PHP Object Injection

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.82 via deserialization of untrusted…

Versions affectées

*-2.2.82

Correctif

2.2.83

Publication

22/11/2024

CVE-2023-3087 Élevée · 7,2
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

FluentSMTP <= 2.2.4 – Unauthenticated Stored Cross-Site Scripting via Email Subject

The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.2.4

Correctif

2.2.5

Publication

06/07/2023

CVE-2023-0219 Faible · 3,8
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

FluentSMTP <= 2.2.2 – Authenticated (Author+) Stored Cross-Site Scripting via Email Logs

The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sending mail (thus adding the payload into the logs of sent emails) in versions up to 2.2.3 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-2.2.2

Correctif

2.2.3

Publication

03/03/2023

CVE-2021-24528 Moyenne · 5,5
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider

FluentSMTP <= 2.0.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to…

Versions affectées

[*, 2.0.1)

Correctif

2.0.1

Publication

29/07/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités