cleantalk
Vulnerabilities and Security Researches

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc, 95230c961ea7801737904d6245f3fe862829cb0d

Published on
Jul 07, 2023
Research Description
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce [wp-sms] < 6.2.0 WP SMS <= 6.1.5 - Cross-Site Request Forgery The WP SMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.5. This is due to missing or incorrect nonce validation on the unSubscriberNumberByUrlAction function. This makes it possible for unauthenticated attackers to unsubscribe users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 6.2.0.
Status
vulnerable