Cross-Site Scripting Vulnerability in SMS Alert Order Notifications for WooCommerce
CVE-2025-26984
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 March 2025
What is CVE-2025-26984?
A vulnerability has been identified in the SMS Alert Order Notifications plugin for WooCommerce that permits reflected Cross-Site Scripting (XSS) attacks. This can occur due to improper neutralization of input during web page generation. Attackers might exploit this vulnerability to inject malicious scripts, potentially compromising users' sensitive information and overall website security. The affected versions range from n/a through 3.7.8, highlighting the need for users to ensure they are running the latest patched version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SMS Alert Order Notifications β WooCommerce <= 3.7.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved