WordPress WP SMS Plugin <= 6.0.4 is vulnerable to Sensitive Data Exposure
CVE-2023-27447
7.5HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 28 December 2023
Summary
The WP SMS – Messaging & SMS Notification plugin by VeronaLabs is prone to a vulnerability that may expose sensitive information to unauthorized users. This issue affects specific versions of the plugin, creating potential risks for websites utilizing it for messaging services within WordPress, WooCommerce, and GravityForms. Website administrators should take immediate action to secure their systems and ensure the confidentiality of user data by updating to the latest versions.
Affected Version(s)
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 6.0.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jarko Piironen (Patchstack Alliance)