External risk intelligence

SQL Injection in Cozy Vision SMS Alert Order Notifications

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-49915

This vulnerability affects a WordPress plugin designed for order notifications. Such plugins are commonly deployed within web applications that are accessible via the public internet to facilitate site functionality, customer interactions, and order processing, making the vulnerable code path regularly exposed.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical SQL injection vulnerability within the SMS Alert Order Notifications feature of Cozy Vision. This type of flaw could potentially allow unauthorized access to sensitive data by manipulating database queries, impacting systems that handle order notifications. The primary concern is to confirm if this specific functionality is in use and exposed to potential risks.

  • The issue involves unauthorized data access.
  • Leadership should remember this for potential data risks.
  • Confirm relevance and any exposure of this feature.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to a website using the vulnerable SMS Alert Order Notifications plugin. Because the plugin improperly handles user-provided data in SQL queries, an attacker can inject malicious SQL code. This could allow them to read sensitive data from the website's database, potentially leading to unauthorized access or data breaches.

  • No authentication required to trigger.
  • Triggered via crafted website requests.
  • Risk of sensitive data exposure.

Live Threat

Current exploitation, exposure, and threat context

A SQL injection vulnerability in SMS Alert Order Notifications could allow an unauthenticated attacker to access and modify sensitive data within the system. This could occur when the application improperly handles user-supplied input when constructing database queries.

  • System database and order information.
  • Via crafted network requests.
  • Unauthorized data access or modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Cozy Vision SMS Alert Order Notifications plugin is susceptible to SQL Injection. Responsibility for addressing this vulnerability likely falls to the application owner or the platform team managing the WordPress instance. The immediate first step is to identify all deployments of the affected plugin, determine their reachability and business criticality, and then prioritize remediation based on exposure and impact.

  • Application or platform team ownership.
  • Confirm plugin presence and exposure.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Cozy Vision SMS Alert Order Notifications plugin?

This is a WordPress plugin designed to automate communication by sending SMS updates regarding store orders. Site administrators install it to integrate real-time alert functionality directly into their e-commerce workflows, allowing the platform to interact with databases to retrieve order details and send notifications to users.

How does SQL injection impact CVE-2025-49915?

This vulnerability falls under the CWE-89 weakness class, meaning the software fails to properly filter special characters in user input. Because the plugin processes this input as part of a database command, an attacker can manipulate the query. This lets them bypass intended logic to extract information from the underlying database that the plugin was never meant to share.

Do I need to be logged in to trigger this vulnerability?

No, authentication is not required to exploit this issue. The vulnerability is triggered by sending specially crafted web requests directly to the plugin's notification functions. Simply visiting the site or performing standard user actions will not trigger the bug; it requires the deliberate delivery of malicious input designed to interfere with SQL query construction.

How do I know if CVE-2025-49915 is relevant to my site?

Halo Surface Signal indicates this is a high-priority concern because order notification plugins are typically active on public-facing websites to handle customer interactions. If your WordPress instance uses this plugin and is accessible over the internet to support your online store, the vulnerable code path is likely reachable by remote attackers.

What steps should I take if I use this plugin?

Begin by auditing your WordPress environment to verify if the SMS Alert Order Notifications plugin is installed and active. Once identified, evaluate the plugin's necessity for your current operations. Coordinate with your technical team to determine if a vendor update is available to patch the code or if the functionality should be disabled until the vulnerability is resolved.

References