Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Jun 27, 2025

YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Vulnerabilities

Review known vulnerability records for the WordPress plugin YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service (`yaysmtp`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-53256, CVE-2025-47587 and CVE-2025-0916, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
3
Patch Coverage
100%
Last Updated
Oct 14, 2025
Priority CVE Quick Links

Fast paths into YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
CVE-2022-2369 High 2.2.1
CVE-2022-2369 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Vulnerability

YaySMTP – Simple WP SMTP Mail <= 2.2 - Sensitive Information Disclosure

CVE-2025-0916 High 2.6.4
CVE-2025-0916 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Stored Cross-Site Scripting

YaySMTP 2.4.9 - 2.6.3 - Unauthenticated Stored Cross-Site Scripting

CVE-2023-3093 High 2.4.6
CVE-2023-3093 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Stored Cross-Site Scripting

YaySMTP <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting via Email

CVE-2022-2370 Medium 2.2.1
CVE-2022-2370 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Sensitive Information Exposure

YaySMTP – Simple WP SMTP Mail <= 2.2 - Missing Authorization to Sensitive Information Exposure

CVE-2022-2371 Medium 2.2.1
CVE-2022-2371 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Stored Cross-Site Scripting

YaySMTP – Simple WP SMTP Mail <= 2.2 - Stored Cross-Site Scripting

CVE-2022-2372 Medium 2.2.2
CVE-2022-2372 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service Stored Cross-Site Scripting

YaySMTP – Simple WP SMTP Mail <= 2.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2025-53256 Medium 2.6.7
CVE-2025-53256 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service SQL Injection

YaySMTP <= 2.6.6 - Authenticated (Administrator+) SQL Injection

CVE-2025-47587 Medium 2.6.5
CVE-2025-47587 YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service SQL Injection

YaySMTP <= 2.6.4 - Authenticated (Administrator+) SQL Injection

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 3 high severity findings.
Recent CVEs
CVE-2025-53256, CVE-2025-47587 and CVE-2025-0916
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-53256
CVE-2025-53256: YaySMTP <= 2.6.6 - Authenticated (Administrator+) SQL Injection

The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...

Published
Jun 27, 2025
Patched Release
2.6.7
Affected Versions
Versions up to 2.6.6
Next Step
Update to 2.6.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-47587
CVE-2025-47587: YaySMTP <= 2.6.4 - Authenticated (Administrator+) SQL Injection

The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...

Published
May 07, 2025
Patched Release
2.6.5
Affected Versions
Versions up to 2.6.4
Next Step
Update to 2.6.5 or newer if supported.
Plugin High Patched: Yes CVE-2025-0916
CVE-2025-0916: YaySMTP 2.4.9 - 2.6.3 - Unauthenticated Stored Cross-Site Scripting

The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.3 due to insufficient input sanitization and output escaping. This makes it possible f...

Published
Feb 18, 2025
Patched Release
2.6.4
Affected Versions
2.4.9 through 2.6.3
Next Step
Update to 2.6.4 or newer if supported.
Plugin High Patched: Yes CVE-2023-3093
CVE-2023-3093: YaySMTP <= 2.4.5 - Unauthenticated Stored Cross-Site Scripting via Email

The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Published
Jun 12, 2023
Patched Release
2.4.6
Affected Versions
Versions up to 2.4.5
Next Step
Update to 2.4.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-2371
CVE-2022-2371: YaySMTP – Simple WP SMTP Mail <= 2.2 - Stored Cross-Site Scripting

The YaySMTP – Simple WP SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings[fromName]' parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

Published
Jul 18, 2022
Patched Release
2.2.1
Affected Versions
Versions before 2.2.1
Next Step
Update to 2.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-2372
CVE-2022-2372: YaySMTP – Simple WP SMTP Mail <= 2.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters, with at least one being the 'client_id' parameter, in versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for...

Published
Jul 15, 2022
Patched Release
2.2.2
Affected Versions
Versions up to 2.2.1
Next Step
Update to 2.2.2 or newer if supported.
Plugin High Patched: Yes CVE-2022-2369
CVE-2022-2369: YaySMTP – Simple WP SMTP Mail <= 2.2 - Sensitive Information Disclosure

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the logs of the plugin

Published
Jul 11, 2022
Patched Release
2.2.1
Affected Versions
2.2 through 2.2
Next Step
Update to 2.2.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-2370
CVE-2022-2370: YaySMTP – Simple WP SMTP Mail <= 2.2 - Missing Authorization to Sensitive Information Exposure

The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them

Published
Jul 11, 2022
Patched Release
2.2.1
Affected Versions
Versions up to 2.2
Next Step
Update to 2.2.1 or newer if supported.