CVSS v3
7.5
HIGH
EPSS Score
75.7 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.
Technical details
- Published
- 2020-12-14
Frequently asked questions
What is CVE-2020-35234?
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.
Is CVE-2020-35234 actively exploited?
Active exploitation of CVE-2020-35234 has not been confirmed. The EPSS score is 75.7%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-35234?
CVE-2020-35234 has a CVSS v3 base score of 7.5 (HIGH severity).
Is CVE-2020-35234 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).