First published: Mon May 12 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications – WooCommerce allows SQL Injection.This issue affects SMS Alert Order Notifications – WooCommerce: from n/a through 3.8.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cozy Vision Technologies SMS Alert Order Notifications | <=3.8.2 | |
Ultimate SMS Notifications for WooCommerce | <=3.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47682 is classified as a critical severity SQL Injection vulnerability.
To address CVE-2025-47682, update the SMS Alert Order Notifications – WooCommerce plugin to version 3.8.3 or later.
CVE-2025-47682 affects versions of SMS Alert Order Notifications – WooCommerce up to and including 3.8.2.
Yes, CVE-2025-47682 can allow attackers to perform unauthorized SQL commands, potentially leading to data breaches.
CVE-2025-47682 is a vulnerability found in the SMS Alert Order Notifications – WooCommerce plugin used on WordPress sites.