« Back to list

Cozyvision

Cozyvision SMS Alert Order Notifications: vulnerabilities and CVEs

Cozyvision SMS Alert Order Notifications has 17 published vulnerabilities, 7 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs17
Last 12 months7
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-95594High (8.1)——Oct 6, 2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
CVE-2026-66424Critical (9.8)0.48%—Aug 13, 2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVE-2026-59540Critical (9.8)0.48%—Jul 23, 2026
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVE-2026-54802High (7.5)0.48%—Jun 17, 2026
Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
CVE-2026-32373Medium (5.4)0.29%—Mar 13, 2026
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from…
CVE-2025-66086Medium (5.3)0.21%—Nov 21, 2025
Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from…
CVE-2025-49915Critical (9.3)0.49%—Oct 22, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order…
CVE-2025-47682Critical (9.8)0.38%—May 12, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order…
CVE-2025-3878Medium (5.4)0.27%—May 10, 2025
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient…
CVE-2025-3876High (8.8)0.44%—May 10, 2025
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to,…
CVE-2024-13553Critical (9.8)0.54%—Apr 1, 2025
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host…
CVE-2025-26988High (7.5)0.52%—Mar 3, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order…
CVE-2025-26984Medium (6.1)0.33%—Mar 3, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Reflected XSS.This issue affects SMS Alert Order…
CVE-2024-11725High (8.8)0.51%—Jan 7, 2025
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the…
CVE-2024-10233Medium (5.4)0.34%—Oct 29, 2024
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient…
CVE-2024-1489Medium (4.3)0.24%—Mar 13, 2024
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the…
CVE-2021-24588Medium (6.1)0.83%—Sep 6, 2021
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application8
  2. T1078 Valid Accounts4
  3. T1005 Data from Local System3
  4. T1068 Exploitation for Privilege Escalation3
  5. T1210 Exploitation of Remote Services2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.