Reflected Cross-Site Scripting in VatanSMS WP SMS Plugin for WordPress
CVE-2026-7462
6.1MEDIUM
What is CVE-2026-7462?
The VatanSMS WP SMS plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) attacks through the page parameter. This vulnerability arises from improper input sanitization and a lack of output escaping in all versions up to and including 1.01. It can allow unauthenticated attackers to inject malicious web scripts, which may execute if they deceive an administrator into clicking a specially crafted link, potentially compromising the security of the web application.
Affected Version(s)
VatanSMS WP SMS 0 <= 1.01