Reflected Cross-Site Scripting Vulnerability in SMS for WordPress Plugin
CVE-2025-12580
6.1MEDIUM
What is CVE-2025-12580?
The SMS for WordPress plugin is susceptible to Reflected Cross-Site Scripting (XSS) through the 'paged' parameter due to inadequate input sanitization and output escaping processes. This vulnerability allows unauthenticated attackers to embed malicious scripts that can run in the context of a user's browser session upon interaction—typically by tricking users into clicking deceptive links. Such exposure underscores the necessity of implementing robust security measures during development to mitigate potential threats.
Affected Version(s)
SMS for WordPress * <= 1.1.8