CVE-2025-26988: WordPress SMS Alert Order Notifications – WooCommerce plugin <= 3.7.8 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.7.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26988?
CVE-2025-26988 is classified as a critical SQL Injection vulnerability affecting versions up to 3.7.8 of SMS Alert Order Notifications – WooCommerce.
How do I fix CVE-2025-26988?
To fix CVE-2025-26988, update the SMS Alert Order Notifications – WooCommerce plugin to the latest version beyond 3.7.8.
What does CVE-2025-26988 affect?
CVE-2025-26988 affects the Cozy Vision SMS Alert Order Notifications – WooCommerce plugin, specifically versions from n/a to 3.7.8.
What is SQL Injection in the context of CVE-2025-26988?
In the context of CVE-2025-26988, SQL Injection refers to the injection of malicious SQL code via user input, potentially allowing attackers to manipulate the database.
Can CVE-2025-26988 lead to data exposure?
Yes, CVE-2025-26988 can lead to data exposure by allowing attackers to execute arbitrary SQL commands on the database.