PT-2026-107849 · WordPress · Sms Alert
CVE-2026-94258
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SMS Alert WordPress plugin versions prior to 4.0.1
Description
In multisite network configurations, the plugin fails to verify if the acting administrator has the necessary permissions to manage selected users before returning their stored billing phone numbers. This allows an administrator of one site to disclose the phone numbers of users belonging to other sites on the same network, provided that the plugin gateway credentials are stored on the acting administrator's site.
Recommendations
Update SMS Alert WordPress plugin to version 4.0.1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sms Alert