PT-2026-22135 · WordPress · Wp Sms

Nguyen Kim Sang

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-28136

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions WP SMS versions through 6.9.12
Description The software contains a flaw due to improper neutralization of special elements used in an SQL command, specifically a SQL Injection issue. This allows for potential manipulation of database queries.
Recommendations Update WP SMS to a version newer than 6.9.12.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-28136

Affected Products

Wp Sms