PT-2026-65406 · WordPress · Sms Alert
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery versions prior to 3.9.8
Description
This software contains a second-order SQL injection, where a malicious payload is first stored in the database and executed later. Authenticated attackers with administrator-level access or higher can inject additional SQL queries through the
checkout payment plans and order status settings using the update option() function. The injection occurs when the cod to prepaid cart notification sendsms hook WP-Cron event triggers the SA CodTOPrepaid::sendSms() function, allowing the extraction of sensitive information from the database due to insufficient escaping of user-supplied parameters and lack of query preparation.Recommendations
Update to a version newer than 3.9.7.
Restrict access to the
checkout payment plans and order status settings to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sms Alert