Exploit/Advisories no image

Published on December 11th, 2023 📆 | 3655 Views ⚑

0

WordPress TextMe SMS 1.9.0 Cross Site Request Forgery – Torchsec


iSpeech

# Exploit Title: WP Plugins TextMe SMS <= 1.9.0 - CSRF
# Date: 09-12-2023
# Exploit Author: Arvandy
# Software Link: https://wordpress.org/plugins/textme-sms-integration/
# Version: 1.9.0
# Tested on: Windows, Linux
# CVE: CVE-2023-48287

# Product Description
This plugin allows you to send SMS messages from your WordPress dashboard to the site owner or to your end users.

# Vulnerability overview
The WordPress plugins TextMe SMS <= 1.9.0 is vulnerable to Cross-Site Request Forgery in the Settings function (Account details and Contact Form 7 Events). This could allow unauthenticated users to trick authenticated users to unintentionally modify the account details and contact form 7 events. This could lead to sensitive data leakage as well as phishing attacks.

# Proof of Concept










# Recommendation
Upgrade to version 1.9.1

Source link

Tagged with:



Comments are closed.