ZeroHour

CVE-2026-81756

niche

Unauthenticated SQL Injection in WordPress Smart Marketing SMS and Newsletters Forms

CVSS 3.1
9.3 critical
EPSS
<1%p16
Published
()
Modified
AI analysis

Smart Marketing SMS and Newsletters Forms, a WordPress plugin for collecting newsletter and SMS subscribers, contains an unauthenticated SQL injection flaw (CWE-89) affecting all versions up to and including 5.1.24. Because the issue requires no authentication (CVSS PR:N) and is reachable over the network with low attack complexity, an unauthenticated attacker can likely trigger it by sending a crafted request to one of the plugin's publicly accessible endpoints, such as the front-end form handlers the plugin provides. Successful exploitation primarily allows the attacker to read data from the site's database (high confidentiality impact); the changed-scope designation suggests the exposed data may be used across the wider site, potentially including subscriber records collected by the plugin, with no integrity loss and at most limited availability impact in the base score. Any WordPress site running the plugin at version 5.1.24 or older is affected. No exploitation is currently known: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and its EPSS estimate (0.3%) is low.

What to do: Sites running Smart Marketing SMS and Newsletters Forms should update to the first release newer than 5.1.24 as soon as a patched version is available. Until then, consider deactivating the plugin if it is not actively used, or apply WAF rules that block SQL injection patterns against the plugin's public endpoints, and review web logs for suspicious unauthenticated requests. After updating, check the WordPress database for signs of unexpected reads or modifications.

Affected
Plainware Smart Marketing SMS and Newsletters Forms (WordPress plugin)<= 5.1.24
Estimated exposure
nichelikely hundreds to low thousands of WordPress sites (exact active-install count not provided in the source data) — No active-install count was included in the provided data, so this estimate is based on the plugin's niche SMS/newsletter feature set within the WordPress ecosystem, where installs map roughly one-to-one to individual sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.