WordPress WP SMS Plugin <= 6.0.4 is vulnerable to Sensitive Data Exposure
CVE-2023-27447

7.5HIGH

Key Information:

Summary

The WP SMS – Messaging & SMS Notification plugin by VeronaLabs is prone to a vulnerability that may expose sensitive information to unauthorized users. This issue affects specific versions of the plugin, creating potential risks for websites utilizing it for messaging services within WordPress, WooCommerce, and GravityForms. Website administrators should take immediate action to secure their systems and ensure the confidentiality of user data by updating to the latest versions.

Affected Version(s)

WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 6.0.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jarko Piironen (Patchstack Alliance)
.