PT-2026-65406 · WordPress · Sms Alert

·

CVE-2026-15673

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery versions prior to 3.9.8
Description This software contains a second-order SQL injection, where a malicious payload is first stored in the database and executed later. Authenticated attackers with administrator-level access or higher can inject additional SQL queries through the checkout payment plans and order status settings using the update option() function. The injection occurs when the cod to prepaid cart notification sendsms hook WP-Cron event triggers the SA CodTOPrepaid::sendSms() function, allowing the extraction of sensitive information from the database due to insufficient escaping of user-supplied parameters and lack of query preparation.
Recommendations Update to a version newer than 3.9.7. Restrict access to the checkout payment plans and order status settings to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15673

Affected Products

Sms Alert