CVE-2023-6980: WP SMS <= 6.5 - Cross-Site Request Forgery to Subscriber Deletion
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the 'delete' action of the wp-sms-subscribers page. This makes it possible for unauthenticated attackers to delete subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6980?
CVE-2023-6980 is classified as a high severity vulnerability due to its potential for Cross-Site Request Forgery.
How do I fix CVE-2023-6980?
To fix CVE-2023-6980, update the WP SMS plugin to version 6.5.1 or higher, which includes patched nonce validation.
What is the risk of exploiting CVE-2023-6980?
Exploiting CVE-2023-6980 could allow an attacker to perform unauthorized actions on behalf of the user, compromising the site's security.
Which versions of WP SMS are affected by CVE-2023-6980?
CVE-2023-6980 affects all versions of the WP SMS plugin up to and including version 6.5.
Does CVE-2023-6980 require user interaction to be exploited?
CVE-2023-6980 can be exploited without user interaction, making it particularly dangerous for website owners.