Impact
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress suffers from a time‑based SQL injection flaw. The vulnerable 'orderby' parameter is incorporated into database queries without proper escaping or prepared statement usage, allowing an attacker with administrator‑level privileges to execute arbitrary SQL. This can result in extraction of sensitive database content, violating confidentiality and potentially allowing further exploitation.
Affected Systems
CozVision treats the plugin as part of WordPress, and the vulnerability applies to all releases up to and including 3.9.7. Administrators or other users with equivalent privileges on the WordPress site that host the plugin are at risk.
Risk and Exploitability
The CVSS base score of 4.9 suggests moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Because the attack requires authenticated access, the likelihood of compromise is limited to sites with admin privileges, but given the ability to exfiltrate data once compromised, any attacker who gains such access can cause significant damage.
OpenCVE Enrichment