
CVE-2023-50843 – WordPress Clockwork SMS Notfications Plugin <= 3.0.4 is vulnerable to SQL Injection
https://notcve.org/view.php?id=CVE-2023-50843
21 Dec 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Clockwork Clockwork SMS Notfications.This issue affects Clockwork SMS Notfications: from n/a through 3.0.4. Neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando SQL ("inyección SQL") en Clockwork Clockwork SMS Notfications. Este problema afecta a Clockwork SMS Notfications: desde n/a hasta 3.0.4. The Clockwork SMS Notfications plugin for WordPress is vulnerable to SQ... • https://patchstack.com/database/vulnerability/mediaburst-email-to-sms/wordpress-clockwork-sms-notfications-plugin-3-0-4-sql-injection-vulnerability?_s_id=cve • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-2701 – Gravity Forms < 2.7.5 - Reflected XSS
https://notcve.org/view.php?id=CVE-2023-2701
21 Jun 2023 — The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page... • https://wpscan.com/vulnerability/298fbe34-62c2-4e56-9bdb-90da570c5bbe • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-17780 – Clockwork SMS Plugins - Multiple Versions - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-17780
18 Dec 2017 — The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and... • https://packetstormsecurity.com/files/145469/Clockwork-SMS-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-18495 – Clockwork SMS Notfications < 2.4.2 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18495
27 Nov 2017 — The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS. El complemento gravity-forms-sms-notifications anterior de 2.4.0 para WordPress tiene XSS. The gravity-forms-sms-notifications plugin before 2.4.2 for WordPress has XSS. • https://wordpress.org/plugins/gravity-forms-sms-notifications/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-18489 – Contact Form 7 – Clockwork SMS < 2.4.1 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18489
27 Nov 2017 — The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS. El complemento contact-form-7-sms-addon anterior de 2.4.0 para WordPress tiene XSS. The Contact Form 7 – Clockwork SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'to' parameter in versions up to 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user ... • https://wordpress.org/plugins/contact-form-7-sms-addon/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-18555 – Booking Calendar - Clockwork SMS <= 1.0.5 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-18555
27 Nov 2017 — The booking-sms plugin before 1.1.0 for WordPress has XSS. El plugin booking-sms anterior a 1.1.0 para WordPress tiene XSS. The Booking Calendar - Clockwork SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘to’ parameter in versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performin... • https://wordpress.org/plugins/booking-sms/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •