A vulnerability labeled as problematic has been found in cozyvision1 SMS Alert Plugin up to 3.9.7 on WordPress. Impacted is the function SA_CodTOPrepaid::sendSms of the component Settings. Executing a manipulation of the argument checkout_payment_plans/order_status can lead to sql injection.

This vulnerability is handled as CVE-2026-15673. The attack can be executed remotely. There is not any exploit available.