CVE-2023-32742

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Aug 30, 2023
Updated: Dec 17, 2024
CWE ID 79

Summary

CVE-2023-32742 is an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 6.1.4 and below of the WP SMS plugin developed by VeronaLabs. An attacker can exploit this vulnerability by injecting malicious scripts into a targeted website, potentially gaining control over user sessions and stealing sensitive information or carrying out other malicious actions. Users of the WP SMS plugin are strongly advised to update to the latest version or apply the necessary patches to mitigate this risk. Unpatched installations remain susceptible to XSS attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Veronalabs Wp Sms

Affected Vendors

  • Verona Labs