cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-sms wp-sms

Direction: descending
Nov 11, 2025

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2025-62006

CVE, Research URL

CVE-2025-62006

Date
Oct 22, 2025
Research Description
Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1.
Affected versions
max 7.0.2.
Status
vulnerable
Aug 20, 2024

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-43331

CVE, Research URL

CVE-2024-43331

Date
Aug 22, 2024
Research Description
Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.
Affected versions
max 6.9.4.
Status
vulnerable
Jun 07, 2024

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-6981

CVE, Research URL

CVE-2023-6981

Date
Jan 03, 2024
Research Description
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter in all versions up to, and including, 6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can leveraged to achieve Reflected Cross-site Scripting.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2021-24561

CVE, Research URL

CVE-2021-24561

Date
Aug 23, 2021
Research Description
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue
Affected versions
max 5.4.9.1.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-6980

CVE, Research URL

CVE-2023-6980

Date
Jan 03, 2024
Research Description
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 6.5.1.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-24881

CVE, Research URL

CVE-2024-24881

Date
Feb 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.5.2.
Affected versions
max 6.5.3.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-30454

CVE, Research URL

CVE-2024-30454

Date
Mar 29, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-34811

CVE, Research URL

CVE-2024-34811

Date
May 14, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.
Affected versions
max 6.5.2.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-27447

CVE, Research URL

CVE-2023-27447

Date
Dec 28, 2023
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.0.4.
Affected versions
max 6.2.0.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2024-25920

CVE, Research URL

CVE-2024-25920

Date
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4.
Affected versions
max 6.4.
Status
vulnerable

WP SMS &#8211; Messaging &amp; SMS Notification for WordPress, WooCommerce, GravityForms, etc # CVE-2023-32742

CVE, Research URL

CVE-2023-32742

Date
Aug 30, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <= 6.1.4 versions.
Affected versions
max 6.2.0.
Status
vulnerable