CVE-2025-54043: WordPress SMTP for Amazon SES plugin <= 1.9 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES allows SQL Injection. This issue affects SMTP for Amazon SES: from n/a through 1.9.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES smtp-amazon-ses allows SQL Injection.This issue affects SMTP for Amazon SES: from n/a through <= 1.9.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54043?
CVE-2025-54043 has a moderate severity level due to potential SQL Injection risks affecting YayCommerce SMTP for Amazon SES.
How do I fix CVE-2025-54043?
To fix CVE-2025-54043, update YayCommerce SMTP for Amazon SES to version 2.0 or later, or implement proper input validation to prevent SQL Injection.
Which versions of YayCommerce SMTP for Amazon SES are affected by CVE-2025-54043?
CVE-2025-54043 affects YayCommerce SMTP for Amazon SES from n/a up to version 1.9.
Can CVE-2025-54043 affect other plugins apart from YayCommerce?
Yes, CVE-2025-54043 also affects WordPress SMTP for Amazon SES up to version 1.9.
What type of vulnerability is CVE-2025-54043?
CVE-2025-54043 is classified as an SQL Injection vulnerability.