Reflected Cross-Site Scripting in VatanSMS WP SMS Plugin for WordPress
CVE-2026-7462

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 May 2026

What is CVE-2026-7462?

The VatanSMS WP SMS plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) attacks through the page parameter. This vulnerability arises from improper input sanitization and a lack of output escaping in all versions up to and including 1.01. It can allow unauthenticated attackers to inject malicious web scripts, which may execute if they deceive an administrator into clicking a specially crafted link, potentially compromising the security of the web application.

Affected Version(s)

VatanSMS WP SMS 0 <= 1.01

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian Chibuike Nwadinobi
.