WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in WP SMS – Ultimate SMS & MMS Notifications, OTP, 2FA, and WooCommerce & Forms Integrations 7.0.1

    Fixed

    The WP SMS plugin for WordPress has a security issue that allows unauthorized access to its features. This means that someone with a Subscriber-level account or higher can perform actions without per...

    Read More
  • Access violation vulnerability in WP SMS – Ultimate SMS & MMS Notifications, 2FA, OTP, and Integrations with WooCommerce, GravityForms, and More 6.9.3

    Fixed

    The WordPress plugin called "WP SMS - Ultimate SMS & MMS Notifications" has a security issue that allows unauthorized people to access it. This is because the plugin does not have a check in plac...

    Read More
  • Input validation vulnerability in WP SMS – Messaging, SMS & MMS Notifications, 2FA & OTP for WordPress, WooCommerce, GravityForms, etc 6.5.1

    Fixed

    The WP SMS plugin for WordPress, which is used for messaging and notifications, has a security vulnerability that allows attackers with administrator-level permissions to inject harmful scripts into ...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.6.2

    Fixed

    The WP SMS plugin for WordPress has a security issue in versions up to 6.6.2. This means that someone who is not logged in can trick a site administrator into doing something they shouldn't by sendin...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.3.4

    Fixed

    The WP SMS plugin for WordPress, which is used for messaging and SMS notifications, has a security issue that allows hackers to insert harmful code into web pages. This can happen when the plugin's s...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.5.2

    Fixed

    The WP SMS plugin for WordPress has a security issue called Reflected Cross-Site Scripting. This happens when the 'page' parameter is not properly checked and cleaned, allowing attackers to insert ha...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.5.1

    Fixed

    The WP SMS plugin for WordPress, WooCommerce, GravityForms, and other platforms is currently at risk of a security threat known as Stored Cross-Site Scripting. This is due to a lack of proper protect...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.5

    Fixed

    The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress has a security vulnerability that could expose sensitive information from the databa...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.5

    Fixed

    The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress has a security vulnerability in all versions up to, and including, 6.5. This means t...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.2.0

    Fixed

    The WP SMS plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery in older versions up to and including version 6.1.5. This is because it lacks proper safety measure...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.1.4

    Fixed

    The WP SMS plugin for WordPress, up to and including version 6.1.4, is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack happens when an attacker injects malic...

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 5.4.13

    Fixed

    Read More
  • Input validation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 5.4.9

    Fixed

    The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress has a security vulnerability in versions up to and including 5.4.9. This means that ...

    Read More
  • Access violation vulnerability in WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc 6.0.4

    Fixed

    The WP SMS plugin for WordPress

    Read More