Junglewise Threat Intelligence

CVE-2026-15670: cozyvision1 SMS Alert SQL injection in orderby parameter

CVE-2026-15670 · Severity: medium · CVSS 4.9 · Published 2026-07-28

Executive brief

The SMS Alert plugin for WooCommerce, which handles order notifications and cart recovery, contains a security flaw that could allow an administrator to extract sensitive information from the website's database. By manipulating specific data sorting parameters, an attacker can run unauthorized database queries. While this requires high-level access, it could lead to the exposure of customer data or internal site configuration.

Technical details

A time-based SQL injection vulnerability exists in the SMS Alert plugin for WordPress due to insufficient escaping and lack of preparation on the 'orderby' parameter within the class-backinstock.php helper. Authenticated attackers with administrator-level privileges can exploit this by appending malicious SQL queries to existing database calls. This allows for the extraction of sensitive information from the database via inference. The issue affects all versions up to 3.9.7; a changeset (3623914) indicates remediation efforts.

Affected products

  • cozyvision1 SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery up to, and including, 3.9.7

Timeline

  • 2026-07-28: advisory: NVD publication date
  • 2026-07-28: disclosed: Wordfence advisory published

References

Related threats