Is the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin safe?
Below are the known, publicly disclosed vulnerabilities of the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery (WordPress) component. If you use it on your site, check the version and update it before the flaw gets exploited.
Known vulnerabilities
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: obejście uwierzytelniania
Obejście uwierzytelniania w komponencie SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. Ocena zagrożenia: Krytyczna (CVSS 9.8). Zaktualizuj podatny komponent do najnowszej wersji lub tymczasowo go wyłącz.
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: przejęcie konta
Przejęcie konta w komponencie SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. Ocena zagrożenia: Krytyczna (CVSS 9.8). Zaktualizuj podatny komponent do najnowszej wersji lub tymczasowo go wyłącz.
How to check whether this affects you
- Check the installed version of the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery component in the admin panel.
- Compare it with the fixed version noted in the details of the relevant vulnerability above.
- If your version is older, update the component to the latest available.
- If a fix has not been released yet, temporarily disable the vulnerable element and watch your logs.
Is this plugin putting your site at risk?
We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are safe.
Request a free audit →