๐Ÿ” CVE Alert

CVE-2023-3213

MEDIUM 5.3

WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_page

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information.

CWE CWE-862
Vendor wpforms (awesome motive)
Product wp mail smtp pro
Published Oct 4, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for wpforms (awesome motive) wp mail smtp pro

Be the first to know when new medium vulnerabilities affecting wpforms (awesome motive) wp mail smtp pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

WPForms (Awesome Motive) / WP Mail SMTP Pro
0 โ‰ค 3.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/a813251b-a4c1-4b23-ad03-dcc1f4f19eb9?source=cve wpmailsmtp.com: https://wpmailsmtp.com/docs/how-to-view-recent-changes-to-the-wp-mail-smtp-plugin-changelog/

Credits

Alex Thomas