Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3.
Published: 2025-06-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper input neutralization in the Smart Notification plugin, allowing an attacker to insert crafted SQL that is executed by the database. Because the injection is blind, the attacker does not receive query results directly but can infer data with repeated requests. Successful exploitation would enable data exfiltration of sensitive information such as user accounts, content, and configuration settings. The weakness corresponds to CWE-89, a classic injection flaw that undermines data confidentiality.

Affected Systems

The issue affects all installations of Smart Notification version 10.3 and earlier from the vendor smartiolabs. No specific build numbers are listed beyond the upper bound of 10.3, so any site running those or older releases is vulnerable.

Risk and Exploitability

A CVSS score of 9.3 marks the flaw as critical, indicating the potential for significant impact if exploited successfully. The EPSS score of less than 1% suggests that while exploitation is unlikely, it is possible enough that continuous vigilance is warranted. The vulnerability is not currently listed in CISA’s KEV catalog, so there is no confirmed widespread exploitation but the high severity warrants action. The likely attack vector is remote interaction with the plugin’s entry points, inferred from the fact that the plugin accepts external input that is incorporated into SQL queries. Exploitation would require access to the site’s network or remote interaction with the plugin’s entry points, but no authentication is required beyond the normal user permissions to exercise the plugin’s functionality.

Generated by OpenCVE AI on May 1, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch by updating Smart Notification to the latest version (10.4 or newer).
  • If an update is not immediately available, fully disable or remove the plugin from the WordPress installation until a fix is released.
  • After patching or removal, review the database for any unauthorized changes or suspicious activity and restrict the database user’s privileges to the minimum needed for the site’s operation.

Generated by OpenCVE AI on May 1, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-18544 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification smio-push-notification allows Blind SQL Injection.This issue affects Smart Notification: from n/a through <= 10.3. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3.
References

Thu, 23 Apr 2026 15:30:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification smio-push-notification allows Blind SQL Injection.This issue affects Smart Notification: from n/a through <= 10.3.
References

Wed, 18 Jun 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3.
Title WordPress Smart Notification Plugin <= 10.3 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:32.347Z

Reserved: 2025-04-16T06:23:51.711Z

Link: CVE-2025-39479

cve-icon Vulnrichment

Updated: 2025-06-17T18:31:55.500Z

cve-icon NVD

Status : Deferred

Published: 2025-06-17T15:15:42.567

Modified: 2026-04-28T19:32:00.490

Link: CVE-2025-39479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:30:11Z

Weaknesses