What is CVE-2026-15673?
This vulnerability affects the 'SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' plugin for WordPress. It allows SQL Injection via the 'checkout_payment_plans' and 'order_status' settings due to insufficient escaping. Versions up to 3.9.7 are impacted, so updating to the latest version is strongly recommended.
Azərbaycanca: Bu zəiflik WordPress üçün 'SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' plagininə təsir edir. 'checkout_payment_plans' və 'order_status' parametrlərində kifayət qədər təmizlənmə olmadığı üçün SQL Injection hücumuna imkan yaradır. Plaginin 3.9.7 və aşağı versiyaları risk altındadır, ona görə də dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which WordPress plugin is affected by CVE-2026-15673?
This vulnerability affects the 'SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery' plugin.
What version of the plugin should be updated to in order to mitigate CVE-2026-15673?
Since versions up to 3.9.7 are impacted, updating to the latest version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.