SQL Injection Vulnerability in SMS Alert Plugin for WooCommerce by WordPress
CVE-2026-15673
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-15673?
The SMS Alert β SMS & OTP for WooCommerce plugin for WordPress is susceptible to generic SQL Injection through 'checkout_payment_plans' and 'order_status' settings. This vulnerability arises from insufficient escaping of user-supplied parameters and poor preparation of SQL queries. Authenticated attackers with administrator-level access can insert malicious SQL queries into existing ones, allowing them to retrieve sensitive database information. This represents a second-order SQL injection as the injected payload can be stored during specific settings updates and executed later through a scheduled WP-Cron event.
Affected Version(s)
SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery 0 <= 3.9.7