
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wp-smsSend SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
Is WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Safe to Use in 2026?
Generally Safe
Score 95/100WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-sms" v7.2 plugin exhibits a mixed security posture. While the static analysis reveals a relatively small attack surface with no apparent unprotected entry points and a high percentage of SQL queries using prepared statements and properly escaped output, there are underlying concerns. The presence of two instances of the `unserialize` function is a significant red flag, as it can lead to remote code execution if not handled with extreme caution and proper input sanitization. Furthermore, the vulnerability history is concerning, with a total of 15 known medium-severity CVEs. The pattern of past vulnerabilities, including Missing Authorization, CSRF, SQL Injection, XSS, and Information Exposure, suggests a history of significant security weaknesses that require ongoing vigilance. The fact that the last vulnerability was in 2026-02-10 is peculiar given typical vulnerability timelines and might indicate an error in the provided data, but if accurate, it suggests recent attention to patching. The plugin's strengths lie in its defensive coding practices like extensive capability checks and proper output escaping for the most part, but the historical CVEs and the use of `unserialize` introduce notable risks that cannot be overlooked.
Key Concerns
- Dangerous function: unserialize used
- Vulnerability history: 15 medium CVEs
- Flows with unsanitized paths
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
15 total CVEs
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce <= 7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP SMS <= 7.0.1 - Missing Authorization
WP SMS <= 6.9.3 - Missing Authorization
WP SMS <= 6.5.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP SMS <= 6.6.2 - Cross-Site Request Forgery
WP SMS <= 6.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP SMS <= 6.5.2 - Reflected Cross-Site Scripting via 'page'
WP SMS <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP SMS <= 6.5 - Cross-Site Request Forgery to Subscriber Deletion
WP SMS <= 6.5 - Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting
WP SMS <= 6.1.5 - Cross-Site Request Forgery
WP SMS <= 6.1.4 - Reflected Cross-Site Scripting via 'delete_mobile'
WP SMS <= 6.0.4 - Information Disclosure via REST API
WP SMS <= 5.4.12 - Authenticated Stored Cross-Site Scripting
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc <= 5.4.9 - Reflected Cross-Site Scripting
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Attack Surface
Shortcodes 1
WordPress Hooks 143
Scheduled Events 1
Maintenance & Trust
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Alternatives
Ultimate SMS Notifications – Messaging, Alerts & OTP
ultimate-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
Branded SMS Pakistan
branded-sms-pakistan
Branded SMS Pakistan - WooCommerce plugin will allow you to send Branded or Short Code SMS notification automatically for orders placed in WooCommerce …
Turbo SMS
turbo-sms
Add Instant Order Status SMS Notifications Feature To Your Site
Bulk SMS – SMSNET24
bulk-sms-smsnet24
SMSNET24.Com is a BULK SMS Service of DigitalLab. Bulk SMS is widely used in Bank, School,College, Universiy, Govt., Non Govt organization world wide.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce Developer Profile
4 plugins · 689K total installs
How We Detect WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-sms/public/css/intlTelInput.min.css/wp-content/plugins/wp-sms/public/js/intel/intlTelInput.min.js/wp-content/plugins/wp-sms/public/js/intel/intel-script.js/wp-content/plugins/wp-sms/public/js/intel/utils.js/wp-content/plugins/wp-sms/public/js/intel/intel-script.jswp-sms/public/css/intlTelInput.min.css?ver=wp-sms/public/js/intel/intlTelInput.min.js?ver=wp-sms/public/js/intel/intel-script.js?ver=wp-sms/public/js/intel/utils.js?ver=HTML / DOM Fingerprints
iti__flagiti__selected-flagiti__arrowiti__country-listiti__countryiti__dial-codeiti__responsive-flagwpsms-user-profile-fields<!-- WP SMS User Profile Fields --><!-- WP SMS Newsletter Form -->data-intl-tel-input-idwp_sms_intel_tel_input/wp-json/wp-sms/v1/settings/wp-json/wp-sms/v1/gateway/wp-json/wp-sms/v1/gateways/wp-json/wp-sms/v1/subscribers/wp-json/wp-sms/v1/template/wp-json/wp-sms/v1/templates/wp-json/wp-sms/v1/send[wp_sms_subscriber_form][wp_sms_gateway_form][wp_sms_template_form][wp_sms_test_sms_form]