First published: Mon Mar 03 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.7.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress SMS Alert Order Notifications – WooCommerce | <=3.7.8 | |
WordPress SMS Alert Order Notifications – WooCommerce | <=3.7.8 |
Update the WordPress SMS Alert Order Notifications – WooCommerce wordpress plugin to the latest available version (at least 3.7.9).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26988 is classified as a critical SQL Injection vulnerability affecting versions up to 3.7.8 of SMS Alert Order Notifications – WooCommerce.
To fix CVE-2025-26988, update the SMS Alert Order Notifications – WooCommerce plugin to the latest version beyond 3.7.8.
CVE-2025-26988 affects the Cozy Vision SMS Alert Order Notifications – WooCommerce plugin, specifically versions from n/a to 3.7.8.
In the context of CVE-2025-26988, SQL Injection refers to the injection of malicious SQL code via user input, potentially allowing attackers to manipulate the database.
Yes, CVE-2025-26988 can lead to data exposure by allowing attackers to execute arbitrary SQL commands on the database.