CVE-2025-3776
HIGHWordPress <1.5 - RCE
Title source: llmDescription
The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().
Exploits (2)
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-3776
References (3)
Scores
CVSS v3
8.3
EPSS
0.0068
EPSS Percentile
71.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Details
CWE
CWE-94
Status
published
Products (1)
cajka/Verification SMS with TargetSMS
< 1.5
Published
Apr 24, 2025
Tracked Since
Feb 18, 2026