Vulnerability record · CVE-2020-35234 · published 14 December 2020
CVE-2020-35234: WordPress Easy WP SMTP plugin logs password-reset links, enabling admin takeover
Wp Ecommerce · Easy Wp Smtp
The Easy WP SMTP plugin before 1.4.4 writes password-reset links into a debug log file stored under the plugin directory. If that directory is listable, an attacker can read the log, request an Administrator password reset, and use the captured link to take over the account. It was exploited in the wild in December 2020.
Description
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated Administrator takeover with confirmed in-the-wild exploitation and very high EPSS, though it requires directory listing to be enabled.
What it is
The Easy WP SMTP plugin before 1.4.4 writes password-reset links into a debug log file stored under the plugin directory. If that directory is listable, an attacker can read the log, request an Administrator password reset, and use the captured link to take over the account. It was exploited in the wild in December 2020.
Impact
An unauthenticated attacker gains full Administrator control of the WordPress site, allowing complete site compromise, content manipulation, and installation of further malicious code.
Attack surface
Reachable over the network with no authentication and no user interaction; the attacker only needs the plugin directory listing to be enabled so the debug log filename can be discovered.
Exploitation
Exploited in the wild in December 2020 per the description and the reference tagged Exploit; not listed in CISA KEV, but EPSS is very high at 0.646 (99.2nd percentile).
What to do
- Update the Easy WP SMTP plugin to 1.4.4 or later immediately.
- Disable directory listing on the web server and block direct HTTP access to the plugin directory.
- Remove or relocate any existing debug log files under wp-content/plugins/easy-wp-smtp/.
- Rotate all WordPress Administrator passwords and invalidate active password-reset links after remediation.
- Restrict or disable plugin debug logging in production.
Detection
- Search web server logs for requests to wp-content/plugins/easy-wp-smtp/ and any *_debug_log.txt files.
- Monitor for password-reset requests followed by immediate successful Administrator logins from the same source.
- Check the filesystem for debug log files in the plugin directory and review their contents for reset links.
- Alert on new Administrator accounts or unexpected plugin/theme changes after a reset event.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/ | ExploitThird Party Advisory |
| https://wordpress.org/plugins/easy-wp-smtp/#developers | ProductRelease NotesThird Party Advisory |
| https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/ | ExploitThird Party Advisory |
| https://wordpress.org/plugins/easy-wp-smtp/#developers | ProductRelease NotesThird Party Advisory |
Track CVE-2020-35234 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35234), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.