SQL Injection Vulnerability in SMS Alert Plugin for WooCommerce by WordPress
CVE-2026-15673

4.4MEDIUM

What is CVE-2026-15673?

The SMS Alert – SMS & OTP for WooCommerce plugin for WordPress is susceptible to generic SQL Injection through 'checkout_payment_plans' and 'order_status' settings. This vulnerability arises from insufficient escaping of user-supplied parameters and poor preparation of SQL queries. Authenticated attackers with administrator-level access can insert malicious SQL queries into existing ones, allowing them to retrieve sensitive database information. This represents a second-order SQL injection as the injected payload can be stored during specific settings updates and executed later through a scheduled WP-Cron event.

Affected Version(s)

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 0 <= 3.9.7

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.