Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 20 vulnerability records associated with SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery, published between 2021 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

20Total records
4Critical
5High
11Medium
0Low
0Informational
20Patched records
0Currently marked unpatched
2021-08-02First disclosure
2026-07-27Latest disclosure
20 of 20CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202111 records
202422 records
202599 records
202688 records

Severity Breakdown

SeverityRecordsShare
Critical420%
High525%
Medium1155%

Vulnerability-Type Breakdown

SQL Injection

6 records30%

First: 2025. Latest: 2026.

Missing Authorization

5 records25%

First: 2025. Latest: 2026.

Cross-Site Scripting

4 records20%

First: 2021. Latest: 2025.

Authentication Bypass

3 records15%

First: 2025. Latest: 2026.

CSRF

1 record5%

First: 2024. Latest: 2024.

Privilege Escalation

1 record5%

First: 2026. Latest: 2026.

Patch Status

Patched
20
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.9.8
  • 3.9.7
  • 3.9.6
  • 3.9.4
  • 3.9.1
  • 3.8.9
  • 3.8.6
  • 3.8.2
  • 3.8.0
  • 3.7.9
  • 3.7.7
  • 3.7.6
  • 3.7.0
  • 3.4.7

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.9.7SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' ParameterJuly 27, 20263.9.8Medium
*-3.9.7SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' SettingsJuly 27, 20263.9.8Medium
*-3.9.7SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' ParameterJuly 27, 20263.9.8Critical
*-3.9.7SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' ParameterJuly 27, 20263.9.8Medium
*-3.9.6SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.6 - Unauthenticated Privilege EscalationJuly 22, 20263.9.7Critical
*-3.9.5SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password ResetJune 30, 20263.9.6Critical
*-3.9.3SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.3 - Missing AuthorizationJune 16, 20263.9.4Medium
*-3.9.0SMS Alert Order Notifications <= 3.9.0 - Missing AuthorizationFebruary 18, 20263.9.1Medium
*-3.8.8SMS Alert Order Notifications <= 3.8.8 - Missing AuthorizationDecember 5, 20253.8.9Medium
*-3.8.5SMS Alert Order Notifications <= 3.8.5 - Unauthenticated SQL InjectionAugust 15, 20253.8.6High
*-3.8.1SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_verify ShortcodeMay 9, 20253.8.2Medium
*-3.8.1SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction FunctionMay 9, 20253.8.2High
*-3.8.1SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Unauthenticated SQL InjectionMay 8, 20253.8.2High
*-3.7.9SMS Alert Order Notifications – WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege EscalationMarch 31, 20253.8.0Critical
*-3.7.8SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Unauthenticated SQL InjectionMarch 2, 20253.7.9High
*-3.7.8SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Reflected Cross-Site ScriptingFebruary 23, 20253.7.9Medium
*-3.7.6SMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options UpdateJanuary 6, 20253.7.7High
*-3.7.5SMSAlert - WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe ShortcodeOctober 28, 20243.7.6Medium
*-3.6.9SMS Alert Order Notifications – WooCommerce <= 3.6.9 - Cross-Site Request ForgeryFebruary 26, 20243.7.0Medium
[*, 3.4.7)SMS Alert Order Notifications – WooCommerce <= 3.4.6 - Cross-Site ScriptingAugust 2, 20213.4.7Medium

Selected source records

Latest Records

MediumCVE-2026-15670

SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

Published: July 27, 2026

Affected versions
*-3.9.7
Patched versions
3.9.8
Original Wordfence record
MediumCVE-2026-15673

SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings

Published: July 27, 2026

Affected versions
*-3.9.7
Patched versions
3.9.8
Original Wordfence record
CriticalCVE-2026-15014

SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter

Published: July 27, 2026

Affected versions
*-3.9.7
Patched versions
3.9.8
Original Wordfence record
MediumCVE-2026-15671

SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter

Published: July 27, 2026

Affected versions
*-3.9.7
Patched versions
3.9.8
Original Wordfence record
CriticalCVE-2026-59540

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.6 - Unauthenticated Privilege Escalation

Published: July 22, 2026

Affected versions
*-3.9.6
Patched versions
3.9.7
Original Wordfence record
CriticalCVE-2026-11387

SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset

Published: June 30, 2026

Affected versions
*-3.9.5
Patched versions
3.9.6
Original Wordfence record
MediumCVE-2026-54802

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.3 - Missing Authorization

Published: June 16, 2026

Affected versions
*-3.9.3
Patched versions
3.9.4
Original Wordfence record
MediumCVE-2026-32373

SMS Alert Order Notifications <= 3.9.0 - Missing Authorization

Published: February 18, 2026

Affected versions
*-3.9.0
Patched versions
3.9.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2026-59540

SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery <= 3.9.6 - Unauthenticated Privilege Escalation

Published: July 22, 2026

Affected versions
*-3.9.6
Patched versions
3.9.7
Original Wordfence record
CriticalCVE-2024-13553

SMS Alert Order Notifications – WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation

Published: March 31, 2025

Affected versions
*-3.7.9
Patched versions
3.8.0
Original Wordfence record
CriticalCVE-2026-15014

SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter

Published: July 27, 2026

Affected versions
*-3.9.7
Patched versions
3.9.8
Original Wordfence record
CriticalCVE-2026-11387

SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset

Published: June 30, 2026

Affected versions
*-3.9.5
Patched versions
3.9.6
Original Wordfence record
HighCVE-2025-3876

SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function

Published: May 9, 2025

Affected versions
*-3.8.1
Patched versions
3.8.2
Original Wordfence record
HighCVE-2024-11725

SMS Alert Order Notifications – WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

Published: January 6, 2025

Affected versions
*-3.7.6
Patched versions
3.7.7
Original Wordfence record
HighCVE-2025-26988

SMS Alert Order Notifications – WooCommerce <= 3.7.8 - Unauthenticated SQL Injection

Published: March 2, 2025

Affected versions
*-3.7.8
Patched versions
3.7.9
Original Wordfence record
HighCVE-2025-49915

SMS Alert Order Notifications <= 3.8.5 - Unauthenticated SQL Injection

Published: August 15, 2025

Affected versions
*-3.8.5
Patched versions
3.8.6
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory