SQL Injection Vulnerability in SMS Alert Order Notifications β WooCommerce by Cozy Vision
CVE-2025-26988
9.3CRITICAL
What is CVE-2025-26988?
A SQL Injection vulnerability exists in the Cozy Vision SMS Alert Order Notifications β WooCommerce plugin, allowing attackers to exploit improper neutralization of special elements in SQL commands. This vulnerability affects all versions up to 3.7.8, posing a significant risk to WordPress sites utilizing this plugin by potentially allowing unauthorized access to the database.
Affected Version(s)
SMS Alert Order Notifications 0 <= 3.7.8