Impact
The SMS Alert – SMS & OTP for WooCommerce plugin is vulnerable to stored Cross‑Site Scripting because the attributes supplied to the sa_verify shortcode are not sanitized or escaped. An authenticated user with contributor or higher privilege can inject arbitrary script code through those attributes, and the script will be stored and served whenever the page containing the shortcode is accessed.
Affected Systems
All WordPress sites running cozyvision’s SMS Alert – SMS & OTP for WooCommerce plugin version 3.8.1 or earlier are affected. The vulnerability targets the plugin’s shortcode handling logic and applies to any page where the sa_verify shortcode is used.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of < 1% and absence from CISA’s KEV catalog suggest low current exploitation likelihood. However, the flaw is easy to exploit by any user with contributor-level permissions, allowing the attacker to inject and execute scripts in the context of site visitors, potentially compromising credentials, defacing content, or redirecting traffic.
OpenCVE Enrichment
EUVD