CVE-2026-81756
9.3Autorius E-goi · Smart Marketing SMS and Newsletters Forms
A critical SQL injection vulnerability in the Smart Marketing SMS and Newsletters Forms plugin allows unauthenticated attackers to query the database.
Executive summary
An unauthenticated SQL injection vulnerability in the Autorius E-goi Smart Marketing SMS and Newsletters Forms plugin poses a critical risk of unauthorized database access.
Vulnerability
The plugin suffers from an unauthenticated SQL injection flaw (CWE-89) that allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database.
Business impact
Successful exploitation of this vulnerability can lead to the unauthorized extraction of sensitive data from the WordPress database, including user information and plugin configuration details. Given the CVSS score of 9.3, this flaw presents a severe risk to data confidentiality and could lead to significant regulatory and reputational consequences for organizations relying on this software.
Remediation
Immediate Action: Update the Smart Marketing SMS and Newsletters Forms plugin to version 5.1.25 or the latest available version immediately.
Proactive Monitoring: Review web server and database access logs for anomalous query patterns, such as unexpected SQL syntax or high volumes of requests to plugin endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection payloads targeting WordPress plugin parameters.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the lack of required authentication for exploitation, necessitates immediate action. Administrators must prioritize updating the plugin to version 5.1.25 to neutralize the risk of database compromise. Until the update is applied, ensure that perimeter security controls are actively monitoring for suspicious traffic directed at the affected plugin endpoints.
Sources
Originally found and disclosed by Supakiad S. (m3ez) | Patchstack Bug Bounty Program, per the CVE Program record.