SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery < 3.9.8 - Authentication Bypass via Account Takeover
critical
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 3.9.8 (exclusive). This makes it possible for unauthenticated attackers to bypass authentication and access other user's accounts, including administ...
- CVSS:
- 9.8
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.8
- Disclosed:
- Aug 24, 2026
CVE-2026-15206 on NVD →
SMS Alert Order Notifications <= 3.9.7 - Unauthenticated Privilege Escalation
high
The SMS Alert Order Notifications plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.7. This is due to a shared OTP session key (sa_mobile_verified) across all form handlers combined with an insufficient phone number check (strpos rather than strict equality, and no require...
- CVSS:
- 7.3
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Aug 6, 2026
CVE-2026-66424 on NVD →
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
medium
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...
- CVSS:
- 4.9
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Jul 27, 2026
CVE-2026-15670 on NVD →
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings
medium
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack o...
- CVSS:
- 4.4
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Jul 27, 2026
CVE-2026-15673 on NVD →
SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter
critical
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phon...
- CVSS:
- 9.8
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Jul 27, 2026
CVE-2026-15014 on NVD →
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter
medium
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...
- CVSS:
- 4.9
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.8
- Disclosed:
- Jul 27, 2026
CVE-2026-15671 on NVD →
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.6 - Unauthenticated Privilege Escalation
critical
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to elevate their privileges.
- CVSS:
- 9.8
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.7
- Disclosed:
- Jul 22, 2026
CVE-2026-59540 on NVD →
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
critical
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like r...
- CVSS:
- 9.8
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Jun 30, 2026
CVE-2026-11387 on NVD →
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.4 - Authenticated (Subscriber+) Privilege Escalation
medium
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.4. This is due to missing validation that the phone number supplied at login matches the phone number that was OTP-verified in the ses...
- CVSS:
- 6.3
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.5
- Disclosed:
- Jun 16, 2026
CVE-2026-54803 on NVD →
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.3 - Missing Authorization
medium
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.3. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 5.3
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.4
- Disclosed:
- Jun 16, 2026
CVE-2026-54802 on NVD →
SMS Alert Order Notifications <= 3.9.0 - Missing Authorization
medium
The SMS Alert Order Notifications plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.1
- Disclosed:
- Feb 18, 2026
CVE-2026-32373 on NVD →
SMS Alert Order Notifications <= 3.8.8 - Missing Authorization
medium
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.8.8
- Fixed in:
- 3.8.9
- Disclosed:
- Dec 5, 2025
CVE-2025-66086 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] <= 3.8.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.
- Affected:
- up to 3.8.8
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66086 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] <= 3.8.5 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5.
- Affected:
- up to 3.8.5
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-49915 on NVD →
SMS Alert Order Notifications <= 3.8.5 - Unauthenticated SQL Injection
high
The SMS Alert Order Notifications plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...
- CVSS:
- 7.5
- Affected:
- up to 3.8.5
- Fixed in:
- 3.8.6
- Disclosed:
- Aug 15, 2025
CVE-2025-49915 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] <= 3.8.2 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications – WooCommerce allows SQL Injection.This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.8.2.
- Affected:
- up to 3.8.2
- Fix:
- No patched version reported
- Disclosed:
- May 12, 2025
CVE-2025-47682 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_verify Shortcode
medium
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...
- CVSS:
- 6.4
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- May 9, 2025
CVE-2025-3878 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function
high
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 8.8
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- May 9, 2025
CVE-2025-3876 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Unauthenticated SQL Injection
high
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...
- CVSS:
- 7.5
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- May 8, 2025
CVE-2025-47682 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.8.0
unknown
[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthen...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Apr 1, 2025
CVE-2024-13553 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation
critical
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticat...
- CVSS:
- 9.8
- Affected:
- up to 3.7.9
- Fixed in:
- 3.8.0
- Disclosed:
- Mar 31, 2025
CVE-2024-13553 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.7.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.
- Affected:
- up to 3.7.9
- Fixed in:
- 3.7.9
- Disclosed:
- Mar 3, 2025
CVE-2025-26984 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.7.9
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.
- Affected:
- up to 3.7.9
- Fixed in:
- 3.7.9
- Disclosed:
- Mar 3, 2025
CVE-2025-26988 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Unauthenticated SQL Injection
high
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...
- CVSS:
- 7.5
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.9
- Disclosed:
- Mar 2, 2025
CVE-2025-26988 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Reflected Cross-Site Scripting
medium
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.1
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.9
- Disclosed:
- Feb 23, 2025
CVE-2025-26984 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.7.7
unknown
[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up to, and including, 3.7.6. This makes it possible for authenti...
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.7
- Disclosed:
- Jan 7, 2025
CVE-2024-11725 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up to, and including, 3.7.6. This makes it possible for authenticated...
- CVSS:
- 8.8
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.7
- Disclosed:
- Jan 6, 2025
CVE-2024-11725 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.7.6
unknown
[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Oct 29, 2024
CVE-2024-10233 on NVD →
SMSAlert - WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode
medium
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...
- CVSS:
- 6.4
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.6
- Disclosed:
- Oct 28, 2024
CVE-2024-10233 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.7.0
unknown
[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages...
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.0
- Disclosed:
- Mar 13, 2024
CVE-2024-1489 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.6.9 - Cross-Site Request Forgery
medium
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and p...
- CVSS:
- 4.3
- Affected:
- up to 3.6.9
- Fixed in:
- 3.7.0
- Disclosed:
- Feb 26, 2024
CVE-2024-1489 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.4.7
unknown
[en] The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.7
- Disclosed:
- Sep 6, 2021
CVE-2021-24588 on NVD →
SMS Alert Order Notifications – WooCommerce <= 3.4.6 - Cross-Site Scripting
medium
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
- CVSS:
- 6.1
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.7
- Disclosed:
- Aug 2, 2021
CVE-2021-24588 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.8.2
unknown
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
CVE-2025-3878 on NVD →
SMS Alert Order Notifications – WooCommerce [sms-alert] < 3.8.2
unknown
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
CVE-2025-3876 on NVD →