Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5.
Published: 2025-10-22
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cozy Vision SMS Alert Order Notifications plugin contains a SQL injection vulnerability caused by insufficient escaping of special characters in database queries. An attacker can supply crafted input to the plugin’s public interface, causing the system to execute arbitrary SQL statements. This allows the attacker to read, modify, or delete data stored in the WordPress database, thereby compromising the confidentiality and integrity of the site’s information.

Affected Systems

All installations of the Cozy Vision SMS Alert Order Notifications WordPress plugin running version 3.8.5 or earlier are affected. The vulnerability applies to every release from the earliest version through <=3.8.5; any WordPress site deploying the plugin at those versions is at risk.

Risk and Exploitability

The CVSS base score of 9.3 reflects a high severity impact. The EPSS score of less than 1% suggests that, as of the latest data, exploit attempts are rare and the vulnerability is not widely leveraged. The plugin is not listed in the CISA KEV catalog. Attackers would need to send maliciously crafted requests to the plugin’s public endpoints, and the vulnerability appears exploitable without requiring authentication. Based on the description, it is inferred that the attack vector is remote via web requests to the plugin’s interface.

Generated by OpenCVE AI on April 30, 2026 at 14:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SMS Alert Order Notifications plugin to a version newer than 3.8.5 from Cozy Vision.
  • If an upgrade cannot be performed immediately, disable or delete the plugin to prevent exposure of the vulnerable code.
  • As an interim protective measure, configure a web application firewall or server rule to block common SQL injection payloads targeting the plugin, and monitor logs for suspicious activity.

Generated by OpenCVE AI on April 30, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}

cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Cozyvision
Cozyvision sms Alert Order Notifications
Wordpress
Wordpress wordpress
Vendors & Products Cozyvision
Cozyvision sms Alert Order Notifications
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.5.
Title WordPress SMS Alert Order Notifications plugin <= 3.8.5 - SQL Injection vulnerability
Weaknesses CWE-89
References

Subscriptions

Cozyvision Sms Alert Order Notifications
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:07.898Z

Reserved: 2025-06-11T16:06:59.982Z

Link: CVE-2025-49915

cve-icon Vulnrichment

Updated: 2025-10-23T14:12:43.788Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:37.440

Modified: 2026-04-27T20:16:16.757

Link: CVE-2025-49915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:00:14Z

Weaknesses