The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 24 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 24 Apr 2025 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo(). | |
| Title | Verification SMS with TargetSMS <= 1.5 - Unauthenticated Limited Remote Code Execution | |
| Weaknesses | CWE-94 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-04-24T08:23:52.626Z
Updated: 2025-04-24T13:06:21.124Z
Reserved: 2025-04-17T17:19:49.099Z
Link: CVE-2025-3776
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-24T13:04:05.257Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-04-24T09:15:31.890
Modified: 2025-04-29T13:52:47.470
Link: CVE-2025-3776
 Redhat
                        Redhat
                    No data.