Executive brief
The WP SMS plugin for WordPress, which allows websites to send SMS notifications to users, contains a security flaw that exposes sensitive subscriber data. An attacker with a basic user account (such as a subscriber) could gain access to private information that should normally be restricted. This data exposure could lead to privacy violations or be used to facilitate further attacks against the website or its users.
Technical details
The WP SMS plugin for WordPress (versions <= 7.2.1) is vulnerable to sensitive data exposure due to an authentication bypass using an alternate path (CWE-288). A remote attacker with Subscriber-level privileges can exploit this flaw to access sensitive information that is intended to be restricted to higher-privileged users. The vulnerability is triggered via a network request and does not require user interaction. The issue has been addressed in version 7.2.2.
Affected products
- VeronaLabs WP SMS <= 7.2.1
Timeline
- 2026-03-23: other: Reported by Jakub Herman
- 2026-04-23: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date