What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Clockwork Clockwork SMS Notfications.This issue affects Clockwork SMS Notfications: from n/a through 3.0.4.
Explanation of Vulnerability in Simple Terms
02Summary
Clockwork SMS Notifications versions up to 3.0.4 contain a SQL injection vulnerability accessible to high-privilege users. An attacker with administrative access can inject malicious SQL commands through the plugin's input fields, potentially reading sensitive database records. The vulnerability requires high-level privileges to exploit and does not allow data modification.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site's database if they have admin-level access.
Potential impact on your site
04Site Impact
An admin account compromise could expose your database contents; monitor admin access logs and update immediately.
Conditions required to exploit
05Prerequisites
Attacker must have high-privilege (admin) account access to the site.
Key dates
06Disclosure timeline
December 28, 2023
CVE published
April 28, 2026
Record updated