VYPR
Critical severity9.3NVD Advisory· Published Mar 3, 2025· Updated Apr 23, 2026

CVE-2025-26988

CVE-2025-26988

Description

SQL Injection vulnerability in SMS Alert Order Notifications plugin allows unauthenticated attackers to execute arbitrary SQL commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL Injection vulnerability in SMS Alert Order Notifications plugin allows unauthenticated attackers to execute arbitrary SQL commands.

The SMS Alert Order Notifications plugin for WordPress suffers from a critical SQL Injection vulnerability due to improper neutralization of special elements used in SQL commands. This flaw affects versions up to and including 3.7.8, allowing attackers to inject malicious SQL queries.[1]

Exploitation does not require authentication, as the vulnerable parameter is accessible to unauthenticated users. Attackers can send crafted requests to the plugin's endpoints, injecting SQL commands that interact with the underlying database. No special network position is needed; any remote attacker can exploit this vulnerability over HTTP.[1]

Successful exploitation can lead to unauthorized access to sensitive data, including user information and credentials. The attacker may also modify or delete database contents, potentially compromising the entire WordPress installation. The CVSS score of 9.3 reflects the severe impact and ease of exploitation.[1]

To mitigate this vulnerability, users must update the plugin to version 3.7.9 or later. Patches have been released, and a mitigation rule is available from Patchstack. As this vulnerability is expected to be exploited in mass campaigns, immediate action is recommended.[1]

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:cozyvision:sms_alert_order_notifications:*:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:cozyvision:sms_alert_order_notifications:*:*:*:*:*:wordpress:*:*range: <3.7.9
    • (no CPE)range: <=3.7.8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.