Zero-day vulnerability fix in WordPress Easy WP SMTP plugin v1.3.9
Incident Report for Liquid Web - Cloud Sites
Resolved
We are resolving this status post but the potential for the vulnerability existing on your sites caused by this plugin are still present should you not update the plugin.

We are available to assist with any questions or concerns via livechat, email at cssupport@liquidweb.com, or by telephone at 1(855)-348-9060.
Posted Mar 27, 2019 - 07:45 CDT
Monitoring
It has been discovered that there was a zero-day vulnerability with the Easy WP SMTP pluigin v1.3.9. This version was prone to a critical zero-day vulnerability that allowed an unauthenticated user to modify WordPress options or to inject and execute code among other malicious actions. A new version (1.3.9.1) has been released and is highly recommended to get that updated as soon as possible.

We are available to assist with any questions or concerns via livechat, email at cssupport@liquidweb.com, or by telephone at 1(855)-348-9060.
Posted Mar 19, 2019 - 17:11 CDT