WP SMS < 5.4.13 - Authenticated Stored Cross-Site Scripting
CVE-2021-24561
5.4MEDIUM
What is CVE-2021-24561?
The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue
Affected Version(s)
WP SMS 5.4.13