Executive brief
The VatanSMS WP SMS plugin for WordPress, which allows site owners to send SMS notifications, is vulnerable to a security flaw that could allow attackers to run malicious scripts in an administrator's browser. By tricking a site administrator into clicking a specially crafted link, an attacker could potentially perform unauthorized actions on the website or steal sensitive session information. This issue affects all versions of the plugin up to and including 1.01.
Technical details
The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'page' parameter. This vulnerability exists in versions up to and including 1.01. An unauthenticated attacker can exploit this by crafting a malicious URL containing a web script and tricking a privileged user, such as an administrator, into clicking it. When the victim visits the link, the script executes within the context of their browser session. This can lead to session hijacking, unauthorized administrative actions, or further site compromise. The issue is rooted in multiple administrative files including groups.php, outbox.php, and subscribers.php.
Affected products
- VatanSMS VatanSMS WP SMS Up to and including 1.01
Timeline
- 2026-05-20: advisory: NVD published the CVE record based on Wordfence data.
References
- https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includes/admin/groups/groups.php
- https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includes/admin/outbox/outbox.php
- https://plugins.trac.wordpress.org/browser/wp-sms-vatansms-com/trunk/includes/admin/subscribers/subscribers.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/96ef8459-1600-4ca0-93c6-0ee42f8adabd?source=cve