Extension WordPress
Vulnérabilités YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports
Cette page rassemble les failles publiées pour YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports
8 fiches
YaySMTP <= 2.6.6 – Authenticated (Administrator+) SQL Injection
The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-2.6.6
2.6.7
27/06/2025
YaySMTP <= 2.6.4 – Authenticated (Administrator+) SQL Injection
The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-2.6.4
2.6.5
07/05/2025
YaySMTP 2.4.9 – 2.6.3 – Unauthenticated Stored Cross-Site Scripting
The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.3 due to insufficient input sanitization and output escaping.…
2.4.9-2.6.3
2.6.4
18/02/2025
YaySMTP <= 2.4.5 – Unauthenticated Stored Cross-Site Scripting via Email
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-2.4.5
2.4.6
12/06/2023
YaySMTP – Simple WP SMTP Mail <= 2.2 – Stored Cross-Site Scripting
The YaySMTP – Simple WP SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[fromName]' parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it…
[*, 2.2.1)
2.2.1
18/07/2022
YaySMTP – Simple WP SMTP Mail <= 2.2.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters, with at least one being the 'client_id' parameter, in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This…
*-2.2.1
2.2.2
15/07/2022
YaySMTP – Simple WP SMTP Mail <= 2.2 – Sensitive Information Disclosure
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the logs of the plugin
2.2
2.2.1
11/07/2022
YaySMTP – Simple WP SMTP Mail <= 2.2 – Missing Authorization to Sensitive Information Exposure
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
*-2.2
2.2.1
11/07/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.