Veronalabs
Veronalabs WP SMS: vulnerabilidades y CVE
Veronalabs WP SMS tiene 15 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40790 | Media (6.5) | 0.34% | — | 15 jun 2026 | Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions. |
| CVE-2026-7462 | Media (6.1) | 0.37% | — | 20 may 2026 | The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. This is due to insufficient input sanitization and output… |
| CVE-2026-28136 | Alta (7.6) | 0.40% | — | 26 feb 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.This issue affects WP SMS: from n/a through <= 6.9.12. |
| CVE-2026-25343 | Media (5.9) | 0.18% | — | 19 feb 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1. |
| CVE-2025-62006 | Media (5.4) | 0.28% | — | 22 oct 2025 | Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1. |
| CVE-2024-43331 | Crítica (9.8) | 0.36% | — | 22 ago 2024 | Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3. |
| CVE-2024-34811 | Media (4.8) | 0.42% | — | 14 may 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1. |
| CVE-2024-30454 | Alta (8.8) | 0.24% | — | 29 mar 2024 | Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2. |
| CVE-2024-25920 | Media (5.4) | 0.32% | — | 27 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.3.4. |
| CVE-2024-24881 | Media (6.1) | 0.38% | — | 8 feb 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected… |
| CVE-2023-6981 | Media (4.9) | 0.41% | — | 3 ene 2024 | The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter in all versions up to, and including, 6.5 due to… |
| CVE-2023-6980 | Media (4.3) | 0.25% | — | 3 ene 2024 | The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing… |
| CVE-2023-27447 | Alta (7.5) | 0.54% | — | 28 dic 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.This issue affects WP SMS – Messaging & SMS… |
| CVE-2023-32742 | Media (6.1) | 0.40% | — | 30 ago 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in VeronaLabs WP SMS plugin <= 6.1.4 versions. |
| CVE-2021-24561 | Media (5.4) | 0.67% | — | 23 ago 2021 | The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.