cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-sms wp-sms

Direction: ascending
Jun 07, 2024

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-6981

CVE, Research URL

CVE-2023-6981

Date
Jan 03, 2024
Research Description
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter in all versions up to, and including, 6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can leveraged to achieve Reflected Cross-site Scripting.
Affected versions
max 6.5.1.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2021-24561

CVE, Research URL

CVE-2021-24561

Date
Aug 23, 2021
Research Description
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue
Affected versions
max 5.4.13.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-6980

CVE, Research URL

CVE-2023-6980

Date
Jan 03, 2024
Research Description
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 6.5.1.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-24881

CVE, Research URL

CVE-2024-24881

Date
Feb 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.5.2.
Affected versions
max 6.5.3.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-30454

CVE, Research URL

CVE-2024-30454

Date
Mar 29, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.
Affected versions
max 6.6.3.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-34811

CVE, Research URL

CVE-2024-34811

Date
May 14, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-27447

CVE, Research URL

CVE-2023-27447

Date
Dec 28, 2023
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.0.4.
Affected versions
max 6.2.0.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-25920

CVE, Research URL

CVE-2024-25920

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4.
Affected versions
max 6.4.
Status
vulnerable

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-32742

CVE, Research URL

CVE-2023-32742

Date
Aug 30, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <= 6.1.4 versions.
Affected versions
max 6.1.5.
Status
vulnerable
Aug 20, 2024

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-43331

CVE, Research URL

CVE-2024-43331

Date
Aug 22, 2024
Research Description
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
Affected versions
max 6.9.4.
Status
vulnerable
Nov 11, 2025

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2025-62006

CVE, Research URL

CVE-2025-62006

Date
Oct 22, 2025
Research Description
Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1.
Affected versions
max 7.0.2.
Status
vulnerable
Feb 28, 2026

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2026-28136

CVE, Research URL

CVE-2026-28136

Date
Feb 26, 2026
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.This issue affects WP SMS: from n/a through <= 6.9.12.
Affected versions
max 7.0.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2026-25343

CVE, Research URL

CVE-2026-25343

Date
Feb 19, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1.
Affected versions
max 7.1.1.
Status
vulnerable
May 02, 2026
Jun 16, 2026

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # 66d2a48446049f0a84abb0461d3eee433fdde3d1

Date
Jun 30, 2021
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 5.4.9.1 WordPress WP SMS plugin <= 5.4.9 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress WP SMS plugin (versions <= 5.4.9).
Affected versions
max 5.4.9.1.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # 95230c961ea7801737904d6245f3fe862829cb0d

Date
Jul 07, 2023
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.2.0 WP SMS <= 6.1.5 - Cross-Site Request Forgery The WP SMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.5. This is due to missing or incorrect nonce validation on the unSubscriberNumberByUrlAction function. This makes it possible for unauthenticated attackers to unsubscribe users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 6.2.0.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # 9f80d9ea-e4ce-4957-9b22-3464446ab003

Date
-
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 5.4.9.1 WP SMS &lt; 5.4.9.1 - Reflected Cross-Site Scripting (XSS) The plugin does not sanitise or escape some of its parameter before outputting them back in the pages, leading to reflected Cross-Site Scripting issues which will be executed in the context of a logged in admin.
Affected versions
max 5.4.9.1.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # c9038d9e6e459de1ff8abd00bd5a0f71e49ef5d8

Date
Jun 30, 2021
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 5.4.9.1 WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 5.4.9 - Reflected Cross-Site Scripting The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 5.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 5.4.9.1.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # 5d24b553d035422e9f15d27c938820151be3e9ba

Date
Jan 15, 2024
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.5.2 WordPress WP SMS Plugin <= 6.5.1 is vulnerable to Cross Site Scripting (XSS) Update the WordPress WP SMS plugin to the latest available version (at least 6.5.2). WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP SMS Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 6.5.2. Have additional information or questions about this entry? Get in touch.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # fbb699ffd6cd26aa92e9fbcfae6975f1a571a917

Date
Jan 12, 2024
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.5.2 WP SMS <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # 4336a858-e642-431f-9d69-9b8b5f6e5e36

Date
-
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.5.2 WP SMS &lt; 6.5.2 - Contributor+ Stored Cross-Site Scripting The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s shortcode(s) in all versions up to, and including, 6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # fc2d7281-abec-475b-8e8d-8dbc47de78da

Date
-
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.2.0 WP SMS &lt; 6.2.0 - User Unsubscribe via CSRF The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Affected versions
max 6.2.0.
Status
vulnerable