Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.9
WP SMS Allows Attackers to Inject Harmful Code into WordPress Sites
CVE-2026-25343
Summary
WP SMS, a plugin used for sending SMS from WordPress, has a security weakness that could allow attackers to inject malicious code into websites. This could lead to unauthorized actions, such as stealing sensitive information or spreading malware. Update to the latest version of WP SMS to fix this issue.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1.
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1.
nvd CVSS3.1
5.9
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026