Executive brief
A security vulnerability exists in a WordPress plugin used to integrate international SMS capabilities with Contact Form 7. This flaw allows an attacker to trick a site administrator into clicking a malicious link, which then executes unauthorized code in the administrator's browser. This could lead to the theft of session cookies, unauthorized administrative actions, or the defacement of the website.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the 'page' parameter of the admin settings interface within the WordPress International SMS for Contact Form 7 Integration plugin (v1.2). The root cause is improper neutralization of user-supplied input in the file 'class-sms-log-display.php'. An unauthenticated remote attacker can exploit this by crafting a malicious URL and enticing a logged-in administrator to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the administrator's session. The plugin has been closed and removed from the WordPress plugin directory due to this security issue.
Affected products
- Varun Sridharan International Sms For Contact Form 7 Integration 1.2
Timeline
- 2021-08-09: other: Plugin closed on WordPress.org due to security issues
- 2022-02-04: disclosed: Initial exploit discovery and PoC creation
- 2026-05-10: advisory: NVD advisory published