Junglewise Threat Intelligence

CVE-2026-81756: Smart Marketing SMS and Newsletters Forms SQL injection

CVE-2026-81756 · Severity: critical · CVSS 9.3 · Published 2026-08-31

Executive brief

Smart Marketing SMS and Newsletters Forms is a WordPress plugin that enables website owners to create and manage SMS and newsletter signup forms. An unauthenticated SQL injection vulnerability in versions 5.1.24 and earlier allows attackers to read, modify, or delete the entire website database, including user accounts and private customer data. This could lead to complete compromise of website operations and customer information theft.

Technical details

The plugin contains a SQL injection vulnerability that can be exploited without authentication. The vulnerability exists in the form processing logic and allows an attacker to inject arbitrary SQL commands through user-controlled input. Since no authentication is required, any unauthenticated attacker with network access to the WordPress site can exploit this vulnerability to execute arbitrary SQL queries, potentially reading sensitive data, modifying database records, or deleting content. The vulnerability has been patched in version 5.1.25 and later.

Affected products

  • Smart Marketing Smart Marketing SMS and Newsletters Forms 5.1.24 and earlier

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: patched in version 5.1.25

References