CVE-2023-27447: WordPress WP SMS Plugin <= 6.0.4 is vulnerable to Sensitive Data Exposure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.0.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27447?
CVE-2023-27447 is considered a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2023-27447?
To fix CVE-2023-27447, update the WP SMS – Messaging & SMS Notification plugin to a version greater than 6.0.4.1.
What are the impacts of CVE-2023-27447?
CVE-2023-27447 allows unauthorized actors to access sensitive information, potentially leading to data leaks.
Which versions of WP SMS are affected by CVE-2023-27447?
CVE-2023-27447 affects all versions of WP SMS – Messaging & SMS Notification for WordPress up to version 6.0.4.1.
Is there a workaround for CVE-2023-27447 before updating?
Currently, the best solution for CVE-2023-27447 is to update to a patched version, as there are no official workarounds available.