Input validation vulnerability in SMTP Mail 1.2.1

The SMTP Mail plugin for WordPress can be affected by a security vulnerability in versions up to and including 1.2.1. Attackers with administrator-level permissions or higher can exploit this vulnerability to add extra SQL queries to existing queries which can be used to gain access to sensitive information stored in the database. This is possible because the plugin doesn’t properly protect against user-supplied parameters or prepare existing SQL queries.

Detected in:

SMTP Mail open vulnerable versions: >= * <= 1.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.