WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce

Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.

17Reported vulnerabilities
7.5Highest CVSS score
7.2.7Latest version
7,000+Active installs

What to do now

Update WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce to 7.2.2 or later. 17 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 8, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24561 Medium 5.4 0.7% 5.4.13 up to (but not including) 5.4.13 5.4.13 August 23, 2021
CVE-2023-27447 High 7.5 0.5% 6.0.4 and earlier 6.0.4.1 December 28, 2023
CVE-2024-25920 Medium 6.4 0.3% 6.3.4 and earlier 6.4 February 14, 2024
WF-c9141ad3-86cf-47ae-be99-d78f0337f2ca Medium 6.4 6.5.1 and earlier 6.5.2 January 12, 2024
CVE-2024-24881 Medium 6.1 0.4% 6.5.2 and earlier 6.5.3 February 8, 2024
CVE-2023-6981 Medium 6.1 0.4% 6.5 and earlier 6.5.1 January 2, 2024
CVE-2023-32742 Medium 6.1 0.4% 6.1.4 and earlier 6.1.5 May 15, 2023
WF-b597e8a5-043e-440e-aaa2-38fb3eeb0731 Medium 6.1 5.4.9 and earlier 5.4.9.1 June 30, 2021
CVE-2024-43331 Medium 5.3 0.4% 6.9.3 and earlier 6.9.4 August 16, 2024
CVE-2026-28136 Medium 4.9 0.3% 6.9.12 and earlier 7.0 June 14, 2025
CVE-2024-34811 Medium 4.4 0.4% 6.5.1 and earlier 6.5.2 May 13, 2024
CVE-2026-40790 Medium 4.3 0.3% 7.2.1 and earlier 7.2.2 April 23, 2026
CVE-2026-25343 Medium 4.4 0.2% 7.1 and earlier 7.1.1 February 10, 2026
CVE-2025-62006 Medium 4.3 0.3% 7.0.1 and earlier 7.0.2 October 16, 2025
CVE-2024-30454 Medium 4.3 0.2% 6.6.2 and earlier 6.6.3 March 28, 2024
CVE-2023-6980 Medium 4.3 0.2% 6.5 and earlier 6.5.1 January 2, 2024
WF-747afa58-182a-4fb3-bfe3-f15db0b1d85a Medium 4.3 Before 6.2.0 6.2.0 July 7, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.