← WordPress Vulnerabilities
WordPress security by component

Smart Marketing SMS and Newsletters Forms

Smart Marketing SMS and Newsletters Forms (smart-marketing-for-wp) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.3.

Plugin slug: smart-marketing-for-wp

CVE-2026-77161: Smart Marketing contact mapping exposes subscriber SQL injection

Smart Marketing SMS and Newsletters Forms through 5.1.24 uses an attacker-controlled parameter name in an insufficiently prepared SQL query. A subscriber can append SQL and extract database information when the plugin's sync feature is enabled and egoi_mapping is configured, both ordinary states for contact mapping. The authoritative export does not name the parameter, action, query, or table.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for smart-marketing-for-wp
Safe version
Sep 12, 2026 CVE-2026-77161
Smart Marketing contact mapping exposes subscriber SQL injection
Smart Marketing SMS and Newsletters Forms through 5.1.24 uses an attacker-controlled parameter name in an insufficiently prepared SQL query. A subscriber can append SQL and extract database information when the plugin's sync feature is enabled and egoi_mapping is configured, both ordinary states for contact mapping. The authoritative export does not name the parameter, action, query, or table.
See mitigation notes
CVE6.5
NVDPending
Aug 31, 2026 CVE-2026-81756
Smart Marketing permits unauthenticated SQL injection
Smart Marketing SMS and Newsletters Forms through 5.1.24 allows unauthenticated attacker-controlled input to reach an unsafe database query. Exploitation can expose database contents and disrupt database-backed site functionality.
5.1.25
CVE9.3
NVDPending
Dec 02, 2024 CVE-2024-53784
Smart Marketing SMS and Newsletters Forms: A security weakness
Smart Marketing SMS and Newsletters Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 01, 2018 CVE-2017-18010
Smart Marketing For Wp: Cross-site scripting
Smart Marketing For Wp is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1