Junglewise Threat Intelligence

CVE-2026-15673: CozyVision SMS Alert for WooCommerce SQL injection in settings

CVE-2026-15673 · Severity: medium · CVSS 4.4 · Published 2026-07-28

Technologies: CozyVision SMS Alert. Vendors: CozyVision.

Executive brief

A security vulnerability exists in the SMS Alert plugin for WooCommerce, which is used to send order notifications and OTPs to customers. An attacker with administrative access could inject malicious code into the plugin's settings, potentially allowing them to steal sensitive information from the website's database. While this requires high-level access to exploit, it could lead to the exposure of customer data or internal site configurations.

Technical details

This is a second-order SQL injection vulnerability (CWE-89) affecting the SMS Alert plugin for WooCommerce. The flaw exists because the 'checkout_payment_plans' and 'order_status' settings are stored via update_option() without sufficient escaping or query preparation. An authenticated attacker with administrator-level privileges can inject malicious SQL payloads into these settings. The payload is later executed when the 'cod_to_prepaid_cart_notification_sendsms_hook' WP-Cron event triggers the SA_CodTOPrepaid::sendSms() function. This can be leveraged to extract sensitive data from the WordPress database. The vulnerability is present in all versions up to and including 3.9.7.

Affected products

  • CozyVision SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery up to, and including, 3.9.7

Timeline

  • 2026-07-28: advisory: Published by Wordfence and NVD

References

Related threats