cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpersian-woocommerce-sms persian-woocommerce-sms

Direction: descending
Feb 28, 2026

افزونه پیامک ووکامرس Persian WooCommerce SMS # CVE-2026-22352

CVE, Research URL

CVE-2026-22352

Date
Feb 20, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PersianScript Persian Woocommerce SMS persian-woocommerce-sms allows Reflected XSS.This issue affects Persian Woocommerce SMS: from n/a through <= 7.1.1.
Affected versions
max 7.1.1.
Status
vulnerable
Jun 15, 2025

افزونه پیامک ووکامرس Persian WooCommerce SMS # CVE-2025-49315

CVE, Research URL

CVE-2025-49315

Date
Jun 06, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PersianScript Persian Woocommerce SMS allows SQL Injection. This issue affects Persian Woocommerce SMS: from n/a through 7.0.10.
Affected versions
max 7.1.0.
Status
vulnerable
Dec 15, 2024

افزونه پیامک ووکامرس Persian WooCommerce SMS # CVE-2024-54312

CVE, Research URL

CVE-2024-54312

Date
Dec 13, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ووکامرس فارسی Persian Woocommerce SMS allows Reflected XSS.This issue affects Persian Woocommerce SMS: from n/a through 7.0.5.
Affected versions
max 7.0.6.
Status
vulnerable
Dec 08, 2024

افزونه پیامک ووکامرس Persian WooCommerce SMS # CVE-2024-10046

CVE, Research URL

CVE-2024-10046

Date
Dec 07, 2024
Research Description
The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 7.0.6.
Status
vulnerable
Oct 17, 2024

افزونه پیامک ووکامرس Persian WooCommerce SMS # CVE-2024-9213

CVE, Research URL

CVE-2024-9213

Date
Oct 17, 2024
Research Description
The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 7.0.3.
Status
vulnerable
Jun 07, 2024

افزونه پیامک ووکامرس Persian WooCommerce SMS # CVE-2016-10987

CVE, Research URL

CVE-2016-10987

Date
Sep 17, 2019
Research Description
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
Affected versions
max 4.4.1.
Status
vulnerable