vendor:
WP-SendSMS
by:
expl0i13r
8,8
CVSS
HIGH
CSRF and Stored XSS
352
CWE
Product Name: WP-SendSMS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wp-sendsms:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2013
WordPress WP-SendSMS v1.0 Plugin CSRF and Stored XSS Vulnerabilities
This wordpress plugin 'WP-SendSMS 1.0' suffers from CSRF vulnerability which can be successfully exploited to trigger Stored XSS vulnerability which in turn sends Wordpress logged in user's cookie to attacker's website. Attacker can also exploit this CSRF vulnerability to change SMS Settings.
Mitigation:
Update to the latest version of the plugin.