cleantalk
Vulnerabilities and Security Researches

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc, 4336a858-e642-431f-9d69-9b8b5f6e5e36

Published on
-
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.5.2 WP SMS &lt; 6.5.2 - Contributor+ Stored Cross-Site Scripting The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s shortcode(s) in all versions up to, and including, 6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 6.5.2.
Status
vulnerable