TextMe SMS
TextMe SMS has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 7.4 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Missing Authorization, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
Every one of the 3 issues recorded for TextMe SMS has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. TextMe SMS is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
TextMe SMS <= 1.8.8 - Authenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records

TextMe SMS
Author
Matat Technologies
TextMe SMS Integration allows you to send SMS messages from your WordPress site using the TextMe SMS gateway service. Features: Send SMS notifications for WooCommerce orders Contact Form 7 integration Elementor Forms integration User registration SMS notifications Admin OTP/2FA for secure logins Phone number login shortcodes Out of stock notifications Balance monitoring with email alerts WooCommerce Integration: New order notifications (customer and admin) Order complete notifications Order cancelled notifications Pending payment reminders Custom order status notifications Customer notes via SMS Login Security: Two-factor authentication via SMS OTP Phone number login support International phone number support
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C