Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-2429: README.txt in ultimate-sms-notifications/trunk – WordPress Plugin Repository

The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.1 via the ‘Export Utility’ functionality. This makes it possible for authenticated attackers, such as a subscriber, to add untrusted input into billing information like their First Name that will embed into the exported CSV file triggered by an administrator and can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVE
#web#git#wordpress#php#auth

1=== Ultimate SMS Notifications for WooCommerce ===2Contributors: homescript , manucastle783Tags: sms, woocommerce, bulk sms, orders notifications sms, WC Twilio4Donate link: https://gumroad.com/homescriptone5Requires at least: 4.46Tested up to: 5.67Requires PHP: 5.6+8Stable tag: trunk9License: GPLv2+10License URI: http://www.gnu.org/licenses/gpl-2.0.txt1112<p>Send Bulk SMS and SMS Notifications made easy. Works with Twilio and Telesign SMS API.</p>1314== Description ==1516<blockquote>17<p>In order to send SMS, open an account on <a href="https://twilio.com" rel="follow">Twilio</a> or <a href="https://telesign.com" rel="follow">Telesign</a> and make sure to have SMS credits on your account.</p>18</blockquote>1920<p><strong>Ultimate SMS Notifications for WooCommerce</strong> is free, simple to configure and allows you to send Bulk SMS and SMS Notifications to your customers automatically your store.</p>2122<p>This plugin works with the two best solutions on the market for delivering SMS : </p>23<ul>24 <li>Twilio</li>25 <li>Telesign</li>26</ul>2728<p>The above solutions offer a reasonable price for sending SMS per country.</p>2930<h4>Features</h4>31<ul>32<li>Get notified by <strong>SMS </strong> as soon as customers buy from your store. </li>33<li>Pre-configured tags are available to easily send your <strong>SMS</strong>.</li>34<li><strong>Send SMS </strong> from customers orders.</li>35<li>Real-time <strong>SMS Notifications</strong> after the customer has purchased from your shop.</li>36<li><strong>Send SMS</strong> to shop manager/owner after order status change.</li>37<li>Send <strong>Bulk SMS</strong> from your store.(Beta) </li>38</ul>39<h4>Documentation</h4>40<p>Find here, how to configure Ultimate SMS Notifications for WooCommerce : <a href="https://homescriptone.gitbook.io/ultimate-sms-notifications-for-woocommerce/" rel="follow">Documentation</a></p>4142<h4>Features request </h4>43<p>If you have a new feature request, feel free to get in touch with us via the <a href="https://wordpress.org/support/plugin/ultimate-sms-notifications/">support forum</a> </p>4445<h4>Addons</h4>46<p>If you want us to create a custom addon for the plugin, contact us <a href="https://homescriptone.com?utm_source=wordpress.org&utm_medium=usn_custom_addon">here</a>, We will be happy to do it for You. </p>4748<h4>Translation</h4>49<ul>50<li>English - Default </li>51</ul>5253<h4>Disclaimer</h4>54<p>This plugin is not affiliated with or supported by Twilio, Inc and Telesign, Inc.<br/> All logos and trademarks are the property of their respective owners.</p>5556<h4>Installation </h4>5758= Automatic installation =5960Automatic installation is the easiest option – WordPress will handles the file transfer, and you won’t need to leave your web browser. To do an automatic install of Ultimate SMS Notifications for WooCommerce, log in to your WordPress dashboard, navigate to the Plugins menu, and click “Add New.”6162In the search field type “Ultimate SMS Notifications for WooCommerce,” then click “Search Plugins.” Once you’ve found us, you can view details about it such as the point release, rating, and description. Most importantly of course, you can install it by! Click “Install Now,” and WordPress will take it from there.6364= Manual installation =6566Manual installation method requires downloading the Ultimate SMS Notifications for WooCommerce plugin and uploading it to your web server via your favorite FTP application. The WordPress codex contains [instructions on how to do this here](https://wordpress.org/support/article/managing-plugins/#manual-plugin-installation).6768== Frequently Asked Questions ==6970= Where can I find Twilio SMS API Keys ? =71Create an account on <a href="https://www.twilio.com/try-twilio">Twilio</a> and follow this <a href="http://bit.ly/38erYBd">tutorial</a> to easily get your API key.7273= Where can I find Telesign SMS API Keys ? =74Create an account on <a href="https://portal.telesign.com/signup"> Telesign </a> and get <a href="https://portal.telesign.com/login"> here </a> your API key in a few clicks.757677=Where can I get support or talk to other users?=78If you get stuck, you can ask for help on the <a href="https://wordpress.org/support/plugin/ultimate-sms-notifications/#new-topic-0">forum</a>.7980== Screenshots ==811. utility page822. options page833. settings page844. testing message sent successfully855. bulk sms866. Create contact list8788== Changelog ==89<h4>1.4.2 - 18 Dec 2020</h4>90<ul>91<li>Added compatibility with WooCommerce 4.7.0</li>92<li>Remove csv export tool</li>93</ul>94<h4>1.4.1 - 02 May 2020</h4>95<ul>96<li>Improving bulk sms features</li>97<li>Remove contact list features</li>98</ul>99<h4>1.4 - 01 May 2020</h4>100<ul>101<li>Added compatibility with WooCommerce 4.0</li>102<li>Documentation links updated</li>103</ul>104<h4>1.3 - 19 August 2019</h4>105<ul>106<li>Adding Customer Contact List Features.</li>107<li>Adding Bulk SMS panels.</li>108<li>Adding different SMS message for each order who will be send.</li>109</ul>110<h4>1.2.3 - 13 July 2019</h4>111<ul>112<li>Fixing bugs who is not sending testing SMS.</li>113<li>Fixing white page bugs when trying to access documentations directly from menu.</li>114</ul>115<h4>1.2.2 - 12 June 2019</h4>116<ul>117<li>Telesign Delivery SMS Bugs fixed.</li>118</ul>119<h4>1.2.1 - 6 June 2019</h4>120<ul>121<li>Twilio integration.</li>122<li>Fixing issue during sending sms to shop owner.</li>123<li>Improving SMS delivering speed.</li>124</ul>125<h4>1.2 - 4 May 2019</h4>126<ul>127<li>Export easily your customer phone numbers into csv.</li>128<li>Send a SMS to shop owner after a succesfull order.</li>129<li>Fixing some bugs with WooCommerce.</li>130</ul>131<h4>1.1.3 - 20 March 2019</h4>132<ul>133<li>Fixing some bugs with WooCommerce</li>134</ul>135<h4>1.1.2 - 18 March 2019</h4>136<ul>137<li>Improvements of the plugin</li>138<li>Fixing some bugs</li>139</ul>140<h4>1.1.1 - 16 March 2019</h4>141<ul>142<li>Optimisation of the plugins</li>143</ul>144<h4>1.1 - 16 March 2019</h4>145<ul>146<li>Optimisation of the plugin</li>147<li>Automatic sms after successfull order.</li>148<li>Possibility to send message if shop manager change order status from processing to on-hold and to completed.</li>149<li>Sending bulk sms from order list in WooCommerce.</li>150</ul>151<h4>1.0.0 - 14 February 2019</h4>152<ul>153<li>First version</li>154</ul>155156== Upgrade Notice ==157<p>Automatic updates should work like a charm; as always though, ensure you backup your site just in case.</p>

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907