Impact
The vulnerability is a missing authorization flaw in the TextMe SMS WordPress plugin that allows attackers to exploit improperly configured access control settings. If exploited, an attacker can gain unauthorized access to plugin configuration or manipulate SMS integration settings, which may lead to further compromise or service disruption. This issue stems from a weakness in the plugin’s access validation logic, classified under CWE‑862.
Affected Systems
The affected product is the Matat Technologies TextMe SMS plugin for WordPress, version 1.9.1 and all earlier releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% signals that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV, but if exploited, the attacker can obtain privileged access to plugin settings via normal web requests. Likely attack vectors include direct HTTP access to the plugin’s administration endpoints or form submissions that bypass security checks. The exploit requires no special authentication, but may need the user to be logged in with a role that has access to the plugin.
OpenCVE Enrichment
EUVD