SQL Injection Vulnerability in SMS Alert Plugin for WooCommerce by WordPress
CVE-2026-15670
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15670?
The SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin is susceptible to a time-based SQL Injection via the 'orderby' parameter. This vulnerability arises from inadequate escaping of user-supplied input and insufficient preparation of the SQL query in versions up to and including 3.9.7. Authenticated attackers with administrator-level access can exploit this flaw to inject additional SQL queries, potentially allowing unauthorized retrieval of sensitive data from the database.
Affected Version(s)
SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 0 <= 3.9.7