CVE-2023-27447

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 28, 2023
Updated: Dec 17, 2024
CWE ID 200

Summary

CVE-2023-27447 is a vulnerability affecting the WP SMS – Messaging & SMS Notification plugin for WordPress, WooCommerce, and GravityForms. The issue exposes sensitive information to unauthorized actors. Specifically, an attacker could potentially gain access to users' API keys, which can be used to send SMS messages on their behalf. This vulnerability affects all versions of the plugin from the initial release through 6.0.4. Users are advised to update the plugin to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Veronalabs Wp Sms

Affected Vendors

  • Verona Labs