Executive brief
Persian Woocommerce SMS is a WordPress plugin used to integrate SMS notification services with e-commerce stores. A security flaw allows a user with 'Shop Manager' privileges to execute unauthorized database commands. This could lead to the theft of sensitive customer information or the modification of store data, though it requires an attacker to already have high-level access to the site.
Technical details
The Persian Woocommerce SMS plugin for WordPress (up to and including version 7.2.2) contains a SQL injection vulnerability (CWE-89). The flaw allows an authenticated attacker with 'Shop Manager' or higher privileges to inject malicious SQL queries into the application's database. This is achieved via network requests without requiring user interaction. Successful exploitation can lead to unauthorized data retrieval (Confidentiality: High) and limited impact on availability. As of the advisory date, no official patch has been released.
Affected products
- PersianScript Persian Woocommerce SMS <= 7.2.2
Timeline
- 2026-06-12: other: Reported by researcher Ananda Dhakal
- 2026-07-23: disclosed: NVD publication date