Unauthenticated SQL Injection Vulnerability in Smart Marketing SMS and Newsletters Forms by WordPress
CVE-2026-81756

9.3CRITICAL

What is CVE-2026-81756?

A vulnerability has been identified in the Smart Marketing SMS and Newsletters Forms plugin for WordPress, allowing unauthenticated SQL injection. Attackers can exploit this flaw in versions up to 5.1.24, potentially leading to unauthorized access and manipulation of the database. This vulnerability underscores the necessity for prompt updates to safeguard user data and maintain the integrity of the product.

Affected Version(s)

Smart Marketing SMS and Newsletters Forms <= 5.1.24

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez) | Patchstack Bug Bounty Program
.