CVE-2023-27447
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 28, 2023
Updated: Dec 17, 2024
CWE ID 200
Summary
CVE-2023-27447 is a vulnerability affecting the WP SMS – Messaging & SMS Notification plugin for WordPress, WooCommerce, and GravityForms. The issue exposes sensitive information to unauthorized actors. Specifically, an attacker could potentially gain access to users' API keys, which can be used to send SMS messages on their behalf. This vulnerability affects all versions of the plugin from the initial release through 6.0.4. Users are advised to update the plugin to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Veronalabs Wp Sms
Affected Vendors
- Verona Labs