Impact
The CAMOO SMS WordPress plugin contains a flaw where user-controlled input is reflected in the generated web page without proper neutralization, enabling attackers to inject malicious JavaScript. This leads to client‑side attacks such as cookie theft, session hijacking, or defacement when a victim visits a crafted URL. The weakness is identified as CWE‑79, and it does not provide remote code execution or privilege escalation beyond the context of the user’s browser.
Affected Systems
The vulnerability affects all installations of the CAMOO SMS plugin from the origin of its releases through version 3.0.1. It is present in the WordPress plugin offered by Camoo Sarl and any site that has an outdated version of the plugin installed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score is below 1%, suggesting a low likelihood of mass exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to entice a user to visit a maliciously crafted link or a page that accepts unfiltered user input. Once the user is tricked, arbitrary JavaScript can run in the context of the site, exposing data to the attacker but not allowing the attacker to alter the site’s server-side code or compromise other users.
OpenCVE Enrichment
EUVD