WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce

WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce has 17 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 17 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 8 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (47%). Other recurring categories include Cross-Site Request Forgery (CSRF), Exposure Of Sensitive Information To An Unauthorized Actor.

Every one of the 17 issues recorded for WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce has a vendor fix available, so running the current release closes all known holes.

13 independent researchers contributed these findings, most of them (2) reported by Krzysztof Zając. WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891012.03.2012Today30.06.20216.1WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 5.4.9 - Reflected Cross-Site Scripting CVSS 6.1 · 30.06.202126.07.20215.5WP SMS <= 5.4.12 - Authenticated Stored Cross-Site Scripting CVSS 5.5 · 26.07.202102.03.20235.3WP SMS <= 6.0.4 - Information Disclosure via REST API CVSS 5.3 · 02.03.202315.05.20236.1WP SMS <= 6.1.4 - Reflected Cross-Site Scripting via 'delete_mobile' CVSS 6.1 · 15.05.202307.07.20234.3WP SMS <= 6.1.5 - Cross-Site Request Forgery CVSS 4.3 · 07.07.202302.01.20244.3WP SMS <= 6.5 - Cross-Site Request Forgery to Subscriber Deletion CVSS 4.3 · 02.01.20246.1WP SMS <= 6.5 - Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting CVSS 6.1 · 02.01.202412.01.20246.4WP SMS <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 12.01.202405.02.20246.1WP SMS <= 6.5.2 - Reflected Cross-Site Scripting via 'page' CVSS 6.1 · 05.02.202414.02.20246.4WP SMS <= 6.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 14.02.202428.03.20244.3WP SMS <= 6.6.2 - Cross-Site Request Forgery CVSS 4.3 · 28.03.202413.05.20244.4WP SMS <= 6.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 13.05.202416.08.20245.3WP SMS <= 6.9.3 - Missing Authorization CVSS 5.3 · 16.08.202414.06.20254.9SMS <= 6.9.12 - Authenticated (Administrator+) SQL Injection CVSS 4.9 · 14.06.202516.10.20254.3WP SMS <= 7.0.1 - Missing Authorization CVSS 4.3 · 16.10.202510.02.20264.4WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 10.02.202623.04.20264.3WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.2.1 - Authenticated (Subscriber+) Information Exposure CVSS 4.3 · 23.04.2026

Strategic Overview

Avg CVSSMedium
5.2/ 10
Patch Coverage100%
Open

0

Fixed

17

Get automatic notifications for all WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-25920

WP SMS <= 6.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Read the full analysis

Vulnerability Records

17 records
2026-04-23 00:00CVE-2026-40790
4.3
Medium
Jakub HermanYes
2026-02-10 00:00CVE-2026-25343
4.4
Medium
Ali Osman ERBAS (0110m4n)Yes
2025-10-16 00:00CVE-2025-62006
4.3
Medium
Denver JacksonYes
2025-06-14 00:00CVE-2026-28136
4.9
Medium
Nguyen Kim SangYes
2024-08-16 00:00CVE-2024-43331
5.3
Medium
Peng ZhouYes
2024-05-13 00:00CVE-2024-34811
4.4
Medium
Dhabaleshwar DasYes
2024-03-28 00:00CVE-2024-30454
4.3
Medium
Peng ZhouYes
2024-02-14 00:00CVE-2024-25920
6.4
Medium
Abu Hurayra (HurayraIIT)Yes
2024-02-05 00:00CVE-2024-24881
6.1
Medium
Dimas MaulanaYes
2024-01-12 00:00N/A
6.4
Medium
AnonymousYes
Showing 1–10 of 17 reports
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce banner
Latestv7.2.8

WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce

VeronaLabs

Author

VeronaLabs

4.1(107)
82/100
Last Updated
2026-09-05 (8d ago)
Active Installs
7,000+
Downloads
770,581
Requires WP
4.1+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2012-03-12 (15y ago)

WSMS lets you send SMS/MMS notifications, one-time passwords (OTP), and two-factor authentication (2FA) messages straight from WordPress. It supports a wide range of SMS gateways and integrates with popular e-commerce and form builder plugins. Use WSMS to: – Keep customers updated on WooCommerce orders – Collect subscribers with SMS newsletter forms – Secure logins with OTP & 2FA – Alert admins about new users, logins, or updates – Run marketing campaigns with scheduled or bulk SMS 👉 Check out the demo | View screenshots | See supported gateways | Explore integrations | Documentation ✨ Key Features Send SMS/MMS: Send messages through your choice of supported SMS gateways. E-Commerce & Form Integration: Seamlessly integrates with popular e-commerce platforms and form builders. OTP & 2FA: Add extra login security with one-time passwords and two-factor authentication. Mobile Login: Let users log in with their mobile number. Admin Alerts: Get notified when new users register, posts are published, or WordPress updates are available. Newsletters & Widgets: Build SMS newsletter forms with shortcodes, widgets, or Gutenberg blocks. Two-Way SMS (All-in-One): Receive and reply to SMS messages inside WordPress. Bulk & Scheduled SMS: Send to multiple recipients at once, immediately or on schedule. Third-Party Integration: Connect with external services and automation platforms. Messaging Button: Let visitors reach you instantly via messaging channels. GDPR Compliant: Built with privacy and compliance in mind. 📡 Supported SMS Gateways WSMS connects to 270+ SMS gateways worldwide. Popular supported gateways by region include: Global: Twilio, Vonage, Plivo, Clickatell, MessageBird, Infobip, Sinch, ClickSend, AWS SNS, Telnyx, GatewayAPI, BulkGate, SMSGlobal, LabsMobile, Octopush, Fortytwo, SMS.to, EasySendSMS, Mitto, Dexatel GCC: Unifonic, Taqnyat, Msegat, OurSMS, Deewan, JawalBSMS, 4jawaly, Zain Middle East: Kavenegar, MeliPayamak, FaraPayamak, Ghasedak, FarazSMS, SMS.ir, ParsGreen, Asanak, AdpDigital, ParsaSMS, SMS Melli, Mediana, Markazpayamak, Sabanovin, IranSMSpanel, Verimor, Bulutfon, NetGSM, VatanSMS, TurboSMS Europe: SMSAPI, Brevo, Esendex, CM.com, LINK Mobility, OVH, Orange, Skebby, Primotexto, Comilio, Aruba, SMSC, CPSMS, SureSMS, ASPSMS, TextAnywhere Asia-Pacific: Fast2SMS, MSG91, Gupshup, Textlocal, MessageMedia, SMSGatewayHub, GuniSMS, ShreeSMS, DirectSend, NHN Cloud, Eskiz, ReveSMS Africa: Africa’s Talking, Hubtel, eBulkSMS, Jusibe, Uwazii Mobile, Hostpinnacle Latin America: SMSMasivos, Sonora Tecnologia, Torpedos Any other provider: Use the built-in Custom Gateway to connect any SMS API (custom HTTP headers, parameters, and raw JSON body supported). 👉 See the full list of supported SMS gateways 💎 Upgrade to WSMS All-in-One Unlock additional features with All-in-One — the plan that gives you access to all premium add-ons in one package. With All-in-One you get: – Secure login & registration with OTP & 2FA – Scheduled & recurring SMS/MMS – Two-way SMS inbox – Enhanced e-commerce features (login, checkout verification, order updates) – Membership platform integrations – Advanced form builder SMS capabilities – Marketing automation integrations – Booking system compatibility – URL shortening service integration – All future add-ons included 👉 See All-in-One details & compare features 🐞 Report Bugs & Security Found a bug? Open an issue on GitHub. Security concerns? Report them via the Patchstack VDP program. 📝 Trademark Notice WooCommerce, GravityForms, Elementor, Contact Form 7, Twilio, WhatsApp, Clickatell, BulkSMS, Plivo, Zapier, Bitly, and other product names mentioned are trademarks of their respective owners. WSMS is not affiliated with, endorsed by, or sponsored by these companies. Source Code and Build Instructions Note: The plugin works out of the box — no build steps required for regular users. This section is for developers who want to modify or contribute to the source code. See the full documentation for user guides. All source code for minified JavaScript and CSS is included in the plugin under the resources/ directory. Build instructions and full source are available on GitHub. Third-Party Libraries Chart.js, flatpickr, intlTelInput, jquery.repeater, jQuery Word and Character Counter, React, Select2, Tailwind CSS, Tooltipster, WP Scoper

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C