← Vulnerability feed

Vulnerability record · CVE-2020-35234 · published 14 December 2020

CVE-2020-35234: WordPress Easy WP SMTP plugin logs password-reset links, enabling admin takeover

Wp Ecommerce · Easy Wp Smtp

The Easy WP SMTP plugin before 1.4.4 writes password-reset links into a debug log file stored under the plugin directory. If that directory is listable, an attacker can read the log, request an Administrator password reset, and use the captured link to take over the account. It was exploited in the wild in December 2020.

7.5 CVSS 3.1 High EPSS 65% · top 0.8% CWE-532 · Sensitive information in log file
7.5CVSS 3.1 base score, v2 5.0
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated Administrator takeover with confirmed in-the-wild exploitation and very high EPSS, though it requires directory listing to be enabled.

What it is

The Easy WP SMTP plugin before 1.4.4 writes password-reset links into a debug log file stored under the plugin directory. If that directory is listable, an attacker can read the log, request an Administrator password reset, and use the captured link to take over the account. It was exploited in the wild in December 2020.

Impact

An unauthenticated attacker gains full Administrator control of the WordPress site, allowing complete site compromise, content manipulation, and installation of further malicious code.

Attack surface

Reachable over the network with no authentication and no user interaction; the attacker only needs the plugin directory listing to be enabled so the debug log filename can be discovered.

Exploitation

Exploited in the wild in December 2020 per the description and the reference tagged Exploit; not listed in CISA KEV, but EPSS is very high at 0.646 (99.2nd percentile).

What to do

  • Update the Easy WP SMTP plugin to 1.4.4 or later immediately.
  • Disable directory listing on the web server and block direct HTTP access to the plugin directory.
  • Remove or relocate any existing debug log files under wp-content/plugins/easy-wp-smtp/.
  • Rotate all WordPress Administrator passwords and invalidate active password-reset links after remediation.
  • Restrict or disable plugin debug logging in production.

Detection

  • Search web server logs for requests to wp-content/plugins/easy-wp-smtp/ and any *_debug_log.txt files.
  • Monitor for password-reset requests followed by immediate successful Administrator logins from the same source.
  • Check the filesystem for debug log files in the plugin directory and review their contents for reset links.
  • Alert on new Administrator accounts or unexpected plugin/theme changes after a reset event.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35234 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-25141Wp-ecommerce easy wp smtp missing authorization vulnerabilityThe Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capabilit…EPSS 4.5%8.8CVE-2022-42699Wp-ecommerce easy wp smtp code injection vulnerabilityAuth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.EPSS 1.4%8.1CVE-2022-45829Wp-ecommerce easy wp smtp path traversal vulnerabilityAuth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.EPSS 0.86%7.2CVE-2022-3334Wp-ecommerce easy wp smtp deserialization of untrusted data vulnerabilityThe Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an a…EPSS 1.2%6.5CVE-2022-45833Wp-ecommerce easy wp smtp path traversal vulnerabilityAuth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.EPSS 0.79%6.1CVE-2017-7723Wp-ecommerce easy wp smtp cross-site scripting vulnerabilityXSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.EPSS 0.78%2.7CVE-2024-3073Wp-ecommerce easy wp smtp vulnerabilityThe Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to,…EPSS 0.33%4.6CVE-2025-24984Windows NTFS logs sensitive information, enabling physical-attack disclosureWindows NTFS writes sensitive information into a log file, which an attacker can read to disclose data. The flaw is rated CVSS 3.1 4.6 (Medium) and a…KEVEPSS 2.0%analysed

Source: NIST National Vulnerability Database (record CVE-2020-35234), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.