WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce

Explore WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce vulnerabilities across all versions. Currently tracking 17 known vulnerabilities, including severity, impact, and patch status.

01234567891012.03.2012Today30.06.20216.1WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 5.4.9 - Reflected Cross-Site Scripting CVSS 6.1 · 30.06.202126.07.20215.5WP SMS <= 5.4.12 - Authenticated Stored Cross-Site Scripting CVSS 5.5 · 26.07.202102.03.20235.3WP SMS <= 6.0.4 - Information Disclosure via REST API CVSS 5.3 · 02.03.202315.05.20236.1WP SMS <= 6.1.4 - Reflected Cross-Site Scripting via 'delete_mobile' CVSS 6.1 · 15.05.202307.07.20234.3WP SMS <= 6.1.5 - Cross-Site Request Forgery CVSS 4.3 · 07.07.202302.01.20244.3WP SMS <= 6.5 - Cross-Site Request Forgery to Subscriber Deletion CVSS 4.3 · 02.01.20246.1WP SMS <= 6.5 - Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting CVSS 6.1 · 02.01.202412.01.20246.4WP SMS <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 12.01.202405.02.20246.1WP SMS <= 6.5.2 - Reflected Cross-Site Scripting via 'page' CVSS 6.1 · 05.02.202414.02.20246.4WP SMS <= 6.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 14.02.202428.03.20244.3WP SMS <= 6.6.2 - Cross-Site Request Forgery CVSS 4.3 · 28.03.202413.05.20244.4WP SMS <= 6.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 13.05.202416.08.20245.3WP SMS <= 6.9.3 - Missing Authorization CVSS 5.3 · 16.08.202414.06.20254.9SMS <= 6.9.12 - Authenticated (Administrator+) SQL Injection CVSS 4.9 · 14.06.202516.10.20254.3WP SMS <= 7.0.1 - Missing Authorization CVSS 4.3 · 16.10.202510.02.20264.4WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 10.02.202623.04.20264.3WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.2.1 - Authenticated (Subscriber+) Information Exposure CVSS 4.3 · 23.04.2026

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce vulnerabilities before they are exploited.

Vulnerability Records

17 records
2026-04-23 00:00CVE-2026-40790
4.3
Medium
Jakub HermanYes
2026-02-10 00:00CVE-2026-25343
4.4
Medium
Ali Osman ERBAS (0110m4n)Yes
2025-10-16 00:00CVE-2025-62006
4.3
Medium
Denver JacksonYes
2025-06-14 00:00CVE-2026-28136
4.9
Medium
Nguyen Kim SangYes
2024-08-16 00:00CVE-2024-43331
5.3
Medium
Peng ZhouYes
2024-05-13 00:00CVE-2024-34811
4.4
Medium
Dhabaleshwar DasYes
2024-03-28 00:00CVE-2024-30454
4.3
Medium
Peng ZhouYes
2024-02-14 00:00CVE-2024-25920
6.4
Medium
Abu Hurayra (HurayraIIT)Yes
2024-02-05 00:00CVE-2024-24881
6.1
Medium
Dimas MaulanaYes
2024-01-12 00:00N/A
6.4
Medium
AnonymousYes
Showing 1–10 of 17 reports
WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce banner
Latestv7.2.5

WSMS (formerly WP SMS) – SMS &amp; MMS Notifications with OTP and 2FA for WooCommerce

VeronaLabs

Author

VeronaLabs

4.1(107)
82/100
Last Updated
2026-05-19 (2mo ago)
Active Installs
7,000+
Downloads
755,419
Requires WP
4.1+
Requires PHP
7.4+
Tested up to
WP 7.0.2
Created
2012-03-12 (15y ago)

WSMS lets you send SMS/MMS notifications, one-time passwords (OTP), and two-factor authentication (2FA) messages straight from WordPress. It supports a wide range of SMS gateways and integrates with popular e-commerce and form builder plugins. Use WSMS to: – Keep customers updated on WooCommerce orders – Collect subscribers with SMS newsletter forms – Secure logins with OTP & 2FA – Alert admins about new users, logins, or updates – Run marketing campaigns with scheduled or bulk SMS 👉 Check out the demo | View screenshots | See supported gateways | Explore integrations | Documentation ✨ Key Features Send SMS/MMS: Send messages through your choice of supported SMS gateways. E-Commerce & Form Integration: Seamlessly integrates with popular e-commerce platforms and form builders. OTP & 2FA: Add extra login security with one-time passwords and two-factor authentication. Mobile Login: Let users log in with their mobile number. Admin Alerts: Get notified when new users register, posts are published, or WordPress updates are available. Newsletters & Widgets: Build SMS newsletter forms with shortcodes, widgets, or Gutenberg blocks. Two-Way SMS (All-in-One): Receive and reply to SMS messages inside WordPress. Bulk & Scheduled SMS: Send to multiple recipients at once, immediately or on schedule. Third-Party Integration: Connect with external services and automation platforms. Messaging Button: Let visitors reach you instantly via messaging channels. GDPR Compliant: Built with privacy and compliance in mind. 💎 Upgrade to WSMS All-in-One Unlock additional features with All-in-One — the plan that gives you access to all premium add-ons in one package. With All-in-One you get: – Secure login & registration with OTP & 2FA – Scheduled & recurring SMS/MMS – Two-way SMS inbox – Enhanced e-commerce features (login, checkout verification, order updates) – Membership platform integrations – Advanced form builder SMS capabilities – Marketing automation integrations – Booking system compatibility – URL shortening service integration – All future add-ons included 👉 See All-in-One details & compare features 🐞 Report Bugs & Security Found a bug? Open an issue on GitHub. Security concerns? Report them via the Patchstack VDP program. 📝 Trademark Notice WooCommerce, GravityForms, Elementor, Contact Form 7, Twilio, WhatsApp, Clickatell, BulkSMS, Plivo, Zapier, Bitly, and other product names mentioned are trademarks of their respective owners. WSMS is not affiliated with, endorsed by, or sponsored by these companies. Source Code and Build Instructions Note: The plugin works out of the box — no build steps required for regular users. This section is for developers who want to modify or contribute to the source code. See the full documentation for user guides. All source code for minified JavaScript and CSS is included in the plugin under the resources/ directory. Build instructions and full source are available on GitHub. Third-Party Libraries Chart.js, flatpickr, intlTelInput, jquery.repeater, jQuery Word and Character Counter, React, Select2, Tailwind CSS, Tooltipster, WP Scoper

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C