CVE-2025-49915

9.3

Cozy Vision · SMS Alert – SMS & OTP for WooCommerce

An SQL injection vulnerability in the SMS Alert plugin for WooCommerce allows unauthenticated attackers to execute arbitrary SQL commands via the plugin.

Executive summary

A critical SQL injection vulnerability in the SMS Alert plugin for WooCommerce (up to v3.8.5) poses a significant risk of unauthorized database access and potential data exfiltration.

Vulnerability

The plugin fails to properly sanitize user-supplied input, leading to an SQL injection vulnerability. This flaw is remotely exploitable by unauthenticated attackers with no user interaction required.

Business impact

The ability to perform SQL injection can lead to the full compromise of the database associated with the WordPress instance, resulting in the theft of customer information, order history, or administrative credentials. Given the CVSS score of 9.3, this vulnerability represents a high risk to data confidentiality and integrity, potentially leading to severe regulatory and reputational damage.

Remediation

Immediate Action: Update the "SMS Alert – SMS & OTP for WooCommerce" plugin to version 3.8.6 or later immediately.

Proactive Monitoring: Review database query logs for unusual activity, such as unexpected syntax errors or suspicious access patterns originating from the web application.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection patterns targeting WordPress plugins.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is highly critical due to its potential for unauthenticated remote exploitation. Organizations using the affected WooCommerce plugin must prioritize updating to version 3.8.6 immediately to eliminate the risk of database compromise.

More Cozy Vision CVEs