Improper access control in Easy WP SMTP - #VU48952
Published: December 14, 2020
Easy WP SMTP
wpecommerce, alexanderfoxc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can access the debug log after the password reset, grab the reset link and take over the admin account.
Note: The vulnerability is being actively exploited in the wild.