SSL Wireless SMS Notification <= 3.5.0 - Unauthenticated SQL Injection
high
The SSL Wireless SMS Notification plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition...
- CVSS:
- 7.5
- Affected:
- up to 3.5.0
- Fixed in:
- 3.6.0
- Disclosed:
- Jan 3, 2025
CVE-2024-56284 on NVD →
SSL Wireless SMS Notification <= 3.6.0 - Unauthenticated Privilege Escalation
critical
The SSL Wireless SMS Notification plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 3.6.0
- Fixed in:
- 3.7.0
- Disclosed:
- Dec 19, 2024
CVE-2024-56220 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database