plugin

Sms Alert Vulnerabilities

35 known security issues reported for the Sms Alert WordPress plugin. Most recent disclosed Aug 24, 2026.

5 critical 6 high 12 medium

Running Sms Alert on your site? Check whether your installed version is affected.

Scan your site free

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery < 3.9.8 - Authentication Bypass via Account Takeover

critical

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass in all versions up to 3.9.8 (exclusive). This makes it possible for unauthenticated attackers to bypass authentication and access other user's accounts, including administ...

CVSS:
9.8
Affected:
up to 3.9.8
Fixed in:
3.9.8
Disclosed:
Aug 24, 2026

CVE-2026-15206 on NVD →

SMS Alert Order Notifications <= 3.9.7 - Unauthenticated Privilege Escalation

high

The SMS Alert Order Notifications plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.7. This is due to a shared OTP session key (sa_mobile_verified) across all form handlers combined with an insufficient phone number check (strpos rather than strict equality, and no require...

CVSS:
7.3
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Aug 6, 2026

CVE-2026-66424 on NVD →

SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

medium

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...

CVSS:
4.9
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Jul 27, 2026

CVE-2026-15670 on NVD →

SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings

medium

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack o...

CVSS:
4.4
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Jul 27, 2026

CVE-2026-15673 on NVD →

SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter

critical

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phon...

CVSS:
9.8
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Jul 27, 2026

CVE-2026-15014 on NVD →

SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter

medium

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...

CVSS:
4.9
Affected:
up to 3.9.7
Fixed in:
3.9.8
Disclosed:
Jul 27, 2026

CVE-2026-15671 on NVD →

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.6 - Unauthenticated Privilege Escalation

critical

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to elevate their privileges.

CVSS:
9.8
Affected:
up to 3.9.6
Fixed in:
3.9.7
Disclosed:
Jul 22, 2026

CVE-2026-59540 on NVD →

SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset

critical

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.9.5. This is due to the plugin not properly validating a user's identity prior to updating their details like r...

CVSS:
9.8
Affected:
up to 3.9.5
Fixed in:
3.9.6
Disclosed:
Jun 30, 2026

CVE-2026-11387 on NVD →

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.4 - Authenticated (Subscriber+) Privilege Escalation

medium

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.9.4. This is due to missing validation that the phone number supplied at login matches the phone number that was OTP-verified in the ses...

CVSS:
6.3
Affected:
up to 3.9.4
Fixed in:
3.9.5
Disclosed:
Jun 16, 2026

CVE-2026-54803 on NVD →

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.3 - Missing Authorization

medium

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.3. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 3.9.3
Fixed in:
3.9.4
Disclosed:
Jun 16, 2026

CVE-2026-54802 on NVD →

SMS Alert Order Notifications <= 3.9.0 - Missing Authorization

medium

The SMS Alert Order Notifications plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.9.0
Fixed in:
3.9.1
Disclosed:
Feb 18, 2026

CVE-2026-32373 on NVD →

SMS Alert Order Notifications <= 3.8.8 - Missing Authorization

medium

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.8.8
Fixed in:
3.8.9
Disclosed:
Dec 5, 2025

CVE-2025-66086 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] <= 3.8.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.

Affected:
up to 3.8.8
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66086 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] <= 3.8.5 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5.

Affected:
up to 3.8.5
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49915 on NVD →

SMS Alert Order Notifications <= 3.8.5 - Unauthenticated SQL Injection

high

The SMS Alert Order Notifications plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

CVSS:
7.5
Affected:
up to 3.8.5
Fixed in:
3.8.6
Disclosed:
Aug 15, 2025

CVE-2025-49915 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] <= 3.8.2 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications – WooCommerce allows SQL Injection.This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.8.2.

Affected:
up to 3.8.2
Fix:
No patched version reported
Disclosed:
May 12, 2025

CVE-2025-47682 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_verify Shortcode

medium

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

CVSS:
6.4
Affected:
up to 3.8.1
Fixed in:
3.8.2
Disclosed:
May 9, 2025

CVE-2025-3878 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function

high

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
8.8
Affected:
up to 3.8.1
Fixed in:
3.8.2
Disclosed:
May 9, 2025

CVE-2025-3876 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Unauthenticated SQL Injection

high

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...

CVSS:
7.5
Affected:
up to 3.8.1
Fixed in:
3.8.2
Disclosed:
May 8, 2025

CVE-2025-47682 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.8.0

unknown

[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthen...

Affected:
up to 3.8.0
Fixed in:
3.8.0
Disclosed:
Apr 1, 2025

CVE-2024-13553 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation

critical

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticat...

CVSS:
9.8
Affected:
up to 3.7.9
Fixed in:
3.8.0
Disclosed:
Mar 31, 2025

CVE-2024-13553 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.7.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.

Affected:
up to 3.7.9
Fixed in:
3.7.9
Disclosed:
Mar 3, 2025

CVE-2025-26984 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.7.9

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.

Affected:
up to 3.7.9
Fixed in:
3.7.9
Disclosed:
Mar 3, 2025

CVE-2025-26988 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Unauthenticated SQL Injection

high

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to a...

CVSS:
7.5
Affected:
up to 3.7.8
Fixed in:
3.7.9
Disclosed:
Mar 2, 2025

CVE-2025-26988 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Reflected Cross-Site Scripting

medium

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 3.7.8
Fixed in:
3.7.9
Disclosed:
Feb 23, 2025

CVE-2025-26984 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.7.7

unknown

[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up to, and including, 3.7.6. This makes it possible for authenti...

Affected:
up to 3.7.7
Fixed in:
3.7.7
Disclosed:
Jan 7, 2025

CVE-2024-11725 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

high

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up to, and including, 3.7.6. This makes it possible for authenticated...

CVSS:
8.8
Affected:
up to 3.7.6
Fixed in:
3.7.7
Disclosed:
Jan 6, 2025

CVE-2024-11725 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.7.6

unknown

[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Oct 29, 2024

CVE-2024-10233 on NVD →

SMSAlert - WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode

medium

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

CVSS:
6.4
Affected:
up to 3.7.5
Fixed in:
3.7.6
Disclosed:
Oct 28, 2024

CVE-2024-10233 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.7.0

unknown

[en] The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages...

Affected:
up to 3.7.0
Fixed in:
3.7.0
Disclosed:
Mar 13, 2024

CVE-2024-1489 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.6.9 - Cross-Site Request Forgery

medium

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the processBulkAction function. This makes it possible for unauthenticated attackers to delete pages and p...

CVSS:
4.3
Affected:
up to 3.6.9
Fixed in:
3.7.0
Disclosed:
Feb 26, 2024

CVE-2024-1489 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.4.7

unknown

[en] The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

Affected:
up to 3.4.7
Fixed in:
3.4.7
Disclosed:
Sep 6, 2021

CVE-2021-24588 on NVD →

SMS Alert Order Notifications – WooCommerce <= 3.4.6 - Cross-Site Scripting

medium

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

CVSS:
6.1
Affected:
up to 3.4.7
Fixed in:
3.4.7
Disclosed:
Aug 2, 2021

CVE-2021-24588 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.8.2

unknown
Affected:
up to 3.8.2
Fixed in:
3.8.2

CVE-2025-3878 on NVD →

SMS Alert Order Notifications &#8211; WooCommerce [sms-alert] < 3.8.2

unknown
Affected:
up to 3.8.2
Fixed in:
3.8.2

CVE-2025-3876 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database