Cross-Site Scripting Vulnerability in Persian WooCommerce SMS Plugin by WordPress
CVE-2016-10987
6.1MEDIUM
What is CVE-2016-10987?
The Persian WooCommerce SMS Plugin for WordPress, prior to version 3.3.4, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially capturing sensitive user information or performing actions on behalf of the user without consent.