Known vulnerabilities in YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports
Free WordPress SMTP plugin with email logs, open & click tracking, reports & charts, CSV export, and WooCommerce email preview.
8Reported vulnerabilities
6.5Highest CVSS score
2.7.6Latest version
10,000+Active installs
What to do now
Update YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports to 2.6.7 or later.
8 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-2370 | Medium | 0.9% | Before 2.2.1 | 2.2.1 |
August 1, 2022 |
| CVE-2022-2371 | Medium | 0.6% | Before 2.2.1 | 2.2.1 |
August 8, 2022 |
| CVE-2022-2372 | Medium | 0.6% | Before 2.2.2 | 2.2.2 |
August 8, 2022 |
| CVE-2022-2369 | Medium | 0.7% | Before 2.2.1 | 2.2.1 |
August 1, 2022 |
| CVE-2025-0916 | Medium | 0.4% | 2.4.9 up to (but not including) 2.6.3 | 2.6.3 |
February 19, 2025 |
| CVE-2023-3093 | Medium | 0.5% | Before 2.4.6 | 2.4.6 |
July 12, 2023 |
| CVE-2025-53256 | Medium | 0.4% | 2.6.6 and earlier | 2.6.7 |
June 27, 2025 |
| CVE-2025-47587 | Medium | 0.4% | 2.6.4 and earlier | 2.6.5 |
May 7, 2025 |