Junglewise Threat Intelligence

CVE-2026-15671: CozyVision SMS Alert SQL injection in id parameter

CVE-2026-15671 · Severity: medium · CVSS 4.9 · Published 2026-07-28

Technologies: CozyVision SMS Alert. Vendors: CozyVision.

Executive brief

A vulnerability exists in the SMS Alert plugin for WordPress, which is used by e-commerce sites to send order notifications and recovery messages. An attacker with administrative access could exploit this flaw to access sensitive information stored in the website's database. While the risk is mitigated by the requirement for high-level access, it could lead to data exposure if an administrator account is compromised.

Technical details

The vulnerability is a generic SQL Injection (CWE-89) located in the 'id' parameter across multiple components including SMSAlert-wc-order-sms.php and class-abandonedcart.php. The root cause is insufficient escaping of user-supplied input and a lack of proper SQL query preparation. An authenticated attacker with administrator-level privileges can append malicious SQL queries to existing ones to exfiltrate data. The issue affects all versions up to and including 3.9.7; a changeset (3623914) indicates a patch has been developed.

Affected products

  • CozyVision SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery up to, and including, 3.9.7

Timeline

  • 2026-07-28: advisory: Published by Wordfence and NVD

References

Related threats