CVE-2025-47682: WordPress SMS Alert Order Notifications – WooCommerce plugin <= 3.8.1 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47682?
CVE-2025-47682 is classified as a critical severity SQL Injection vulnerability.
How do I fix CVE-2025-47682?
To address CVE-2025-47682, update the SMS Alert Order Notifications – WooCommerce plugin to version 3.8.3 or later.
What versions are affected by CVE-2025-47682?
CVE-2025-47682 affects versions of SMS Alert Order Notifications – WooCommerce up to and including 3.8.2.
Can CVE-2025-47682 lead to data breaches?
Yes, CVE-2025-47682 can allow attackers to perform unauthorized SQL commands, potentially leading to data breaches.
Is CVE-2025-47682 specifically a WordPress vulnerability?
CVE-2025-47682 is a vulnerability found in the SMS Alert Order Notifications – WooCommerce plugin used on WordPress sites.