CVE-2025-3434

Published
View on NVD ↗
CVSS v3
7.2
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p><strong>Send WordPress emails through Amazon SES server using YaySMTP</strong></p> <p><strong>Amazon Simple Email Service (SES)</strong> is a versatile mail service provider. It is a powerhouse for sending emails, but tapping into its full potential within WordPress can be tricky&#8230; until now!</p> <p>Introducing YaySMTP, your seamless bridge between <strong>Amazon SES and WordPress</strong> for turbocharged email delivery.</p> <p>It costs nothing to connect with AWS / Amazon SES.</p> <p>YaySMTP for WP SES comes without baffling configuration options. Any WordPress beginner can set it up successfully.</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/siEe9YyPg6k?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>Moreover, this WP SES plugin provides advanced options that you can&#8217;t find in other Amazon SES SMTP free plugins.</p> <ul> <li><strong>Easy to set up</strong>: Clear interface and simple user experience. </li> <li><strong>Boosted deliverability</strong>: Experience lightning-fast email sending and enhanced reliability—no more frustrating delays.</li> <li><strong>Email log</strong>: Set time frame for auto-delete, show/hide columns.</li> <li><strong>Email actions</strong>: Display, search, view, and delete emails easily.</li> <li><strong>Send test email</strong>: One click to send an email for testing.</li> <li><strong>Compact UI</strong>: Do everything without leaving the page or browser tab.</li> <li><strong>Detailed tracking</strong>: Monitor email performance like a pro with comprehensive analytics and insights into opens, clicks, senders, etc.</li> <li><strong>Export/Import</strong>: Quickly export your CSV files to reserve the email sending history.</li> </ul> <h3>⚡️ HOW IT WORKS</h3> <p>YaySMTP plugin makes Amazon SES server and your WordPress site become friends very quickly.</p> <p>To enable SES SMTP for your WordPress emails, you will need to register an <a href="https://portal.aws.amazon.com/billing/signup#/start" rel="nofollow ugc">AWS account</a>.</p> <p>Amazon&#8217;s SMTP service provider offers an affordable Pay-as-you-go plan, if not the best and cheapest.</p> <p>The configuration process is easy. Just follow our <a href="https://yaycommerce.gitbook.io/yaysmtp/how-to-set-up-smtps/how-to-connect-amazon-ses" rel="nofollow ugc">WP SES documentation</a>, and it takes you only a few minutes.</p> <p>If you want hands-free setup support, just buy <a href="https://yaycommerce.com/yaysmtp-wordpress-mail-smtp/" rel="nofollow ugc">YaySMTP</a> and let us handle all the config. Our team is always ready to help you unleash the full power of WordPress SMTP and Amazon SES.</p> <h3>🎏 Supported Themes and Plugins</h3> <ul> <li>Complete compatibility with all themes, page builders, and major plugins.</li> <li>Perfect with <a href="https://yaycommerce.com/yaymail-woocommerce-email-customizer/" rel="nofollow ugc">YayMail &#8211; WooCommerce Email Customizer</a> plugin.</li> </ul> <h3>📝 Documentation and Support</h3> <p>If you&#8217;re having issues, do let us know, and we&#8217;ll be <a href="https://yaycommerce.com/support/" rel="nofollow ugc">happy to help</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
36.7K