cleantalk
Vulnerabilities and Security Researches

YaySMTP – Simple WP SMTP Mail, CVE-2025-47587

CVE, Research URL

CVE-2025-47587

Published on
May 07, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.
Affected versions
Min -, max 2.6.5.
Status
vulnerable