WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.2.1 - Authenticated (Subscriber+) Information Exposure
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
Minimum safe version
7.2.2
Update to 7.2.2 or later to address 22 fixable vulnerabilities
CVE-2026-28136
CVE-2026-25343
CVE-2025-62006
CVE-2024-43331
CVE-2024-34811
WP SMS < 6.5.2 - Contributor+ Stored Cross-Site Scripting
CVE-2024-30454
CVE-2024-25920
CVE-2024-24881
WordPress WP SMS Plugin <= 6.5.1 is vulnerable to Cross Site Scripting (XSS)
WP SMS <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-6981
CVE-2023-6980
WP SMS < 6.2.0 - User Unsubscribe via CSRF
WP SMS < 5.4.9.1 - Reflected Cross-Site Scripting (XSS)
WP SMS <= 6.1.5 - Cross-Site Request Forgery
CVE-2023-32742
CVE-2023-27447
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 5.4.9 - Reflected Cross-Site Scripting
WordPress WP SMS plugin <= 5.4.9 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress WP SMS Plugin < 5.4.13 is vulnerable to Cross Site Scripting (XSS)